FinStitch← Back to home

Security

Last updated 20 July 2026

Security is fundamental to how we design, build and operate FinStitch. You trust us with highly sensitive financial information, and we protect it with strong technical, organisational and operational controls — designed to safeguard your data, maintain its confidentiality and integrity, and keep our service reliable.

Our security principles

  • Protect customer data at every stage of its lifecycle.
  • Minimise the amount of data we collect and retain.
  • Apply least-privilege access controls.
  • Build security into every stage of software development.
  • Continuously monitor and improve our security posture.
  • Respond quickly to emerging threats and vulnerabilities.

Encryption

Your data is protected both in transit and at rest using modern encryption.

Data in transit

All communication between your device and FinStitch is encrypted using HTTPS with modern Transport Layer Security (TLS), protecting your information as it travels over the internet.

Data at rest

  • Sensitive information stored by FinStitch is encrypted using industry-standard techniques.
  • Broker API credentials are encrypted with AWS KMS, and application secrets are managed using AWS Secrets Manager and AWS KMS.
  • Encryption keys are never exposed to users or stored alongside the encrypted data.

Authentication & account security

We use Amazon Cognito for authentication. Cognito handles password storage and hashing using industry-standard mechanisms — we never see or store your password. Our authentication includes:

  • Passkeys (WebAuthn) — sign in with Face ID, Touch ID or a hardware security key, with no password to phish.
  • Two-factor authentication (TOTP) — one-time codes from your authenticator app.
  • Recovery codes — one-time backup codes (shown once, stored only as secure hashes) so you can regain access if you lose your authenticator.
  • Biometric unlock — lock the app behind Face ID or Touch ID, toggled per device.
  • Account verification via email during registration.
  • Protection against common authentication attacks.

Security tools in your hands

  • Device management — see every device signed in to your account and revoke any of them.
  • Login activity — a history of sign-ins with device, location and outcome (including blocked and challenged attempts).
  • Session control — review active sessions, revoke them individually, or sign out everywhere at once.
  • Security score — an in-app checklist that scores your account's security posture and shows exactly what to improve.
  • Step-up re-authentication — sensitive actions (like changing 2FA, viewing recovery codes or revoking devices) require you to re-authenticate first, even inside an active session.

You are responsible for keeping your account credentials confidential, and should notify us immediately if you suspect unauthorised access.

Connected financial accounts

When you connect financial accounts through supported providers:

  • Broker connections are designed to be read-only — we only request read permissions when you connect, and FinStitch has no features to place trades, withdraw money or change anything in your account.
  • We only request the permissions required to provide the features you choose.
  • You can disconnect a connected account at any time — your API keys are deleted immediately and irreversibly when you do.

Open Banking security

Where you connect a bank account through a regulated Open Banking provider:

  • You authenticate directly with your financial institution or authorised provider.
  • Your online banking credentials are never shared with or stored by FinStitch.
  • Access to your financial information is granted only with your explicit consent.
  • You can revoke access at any time through FinStitch or your financial institution, where supported.

Infrastructure security

FinStitch is hosted on Amazon Web Services (AWS) in the United Kingdom (London / eu-west-2), designed with security, reliability and resilience in mind. We use managed AWS services wherever possible to reduce operational risk, with secure configuration management, separation of development and production environments, secure deployment processes, continuous infrastructure monitoring, and backup and disaster-recovery procedures.

Access controls

Access to customer information is restricted based on business need. We apply the principle of least privilege so team members receive only the access necessary for their responsibilities. Administrative access is restricted and monitored, and permissions are reviewed periodically and removed when no longer required.

Application security

Security is incorporated throughout our software development lifecycle. Our practices include secure development practices, code reviews, dependency management, timely security updates, input validation and output encoding where appropriate, and protection against common web-application vulnerabilities.

Monitoring & logging

We continuously monitor our systems to help identify security issues and maintain reliability — including infrastructure health, application errors, security-related events and service availability. Authentication activity is logged, and Amazon Cognito's advanced security features flag and challenge risky sign-in attempts. Relevant logs are reviewed where appropriate to support incident investigation and platform integrity.

Incident response

We maintain procedures for responding to security incidents. If one occurs, we aim to detect it promptly, contain and investigate the issue, restore affected services where necessary, notify affected users and relevant authorities where required by law, and put measures in place to reduce the likelihood of recurrence.

Vulnerability management

We continuously assess and improve the security of our platform through regular software updates, timely application of security patches, monitoring for newly disclosed vulnerabilities, and reviewing and improving our security controls as the platform evolves.

Responsible disclosure

We welcome responsible disclosure of security vulnerabilities. If you believe you've found a security issue affecting FinStitch, please email security@finstitch.com with as much detail as possible, and give us a chance to resolve it before disclosing publicly. See our Responsible Disclosure page for full details.

Privacy & data protection

Privacy and security work together. We process personal information in accordance with our Privacy Policy and applicable data protection laws, with data minimisation, purpose limitation, appropriate retention periods, user control over connected accounts, and secure deletion of information where appropriate. You own your data, we do not sell it, and you can request deletion of your account and associated data at any time. We carry out Data Protection Impact Assessments for high-risk processing, so privacy risks are identified and mitigated before we build.

Business continuity

We maintain operational processes designed to support service continuity and data resilience, including regular backups, disaster-recovery planning, infrastructure redundancy where appropriate, and ongoing monitoring of critical systems. No system can guarantee uninterrupted availability, but we continuously work to improve the resilience of our platform.

An ongoing commitment

Security is not a one-time effort. As technology, threats and regulations evolve, we continually review and strengthen our practices, and will adopt additional industry standards and certifications where appropriate as FinStitch grows.

Contact us

Questions about our security practices, or want to report a concern? Contact our security team at security@finstitch.com, or for general help, support@finstitch.com.

© 2026 FinStitch
Trust CenterSecurityPrivacyTermsHome