Information Security Policy
Last updated: August 9, 2026
Budgetmend is operated by Kaai Tech LLC. Questions: support@budgetmend.com.
Version: 1.1 · Effective date:August 9, 2026 · Owner: Kaai Tech LLC — Information Security Lead · Contact: security@budgetmend.com
1. Purpose
This policy defines how Budgetmend identifies, mitigates, and monitors information security risks for our budgeting application and the consumer financial data we process through approved third-party partners.
2. Scope
Applies to all Budgetmend systems, personnel, and contractors with access to production data or infrastructure, including:
- Production web application and APIs
- Authentication, database, and file storage services
- Payment and bank-linking integrations
- Source code repositories and deployment pipelines
A current list of subprocessors is published in our Privacy Policy.
3. Roles and responsibilities
- Information Security Lead: Policy ownership, incident response, access reviews, and third-party security liaison
- Engineering: Secure development, vulnerability remediation, access controls, and API authorization
- All personnel: MFA on accounts, secure devices, report incidents within 24 hours
4. Risk management
- Security risks are reviewed when launching features that handle financial or authentication data
- Third-party processors receive only the minimum data necessary to provide their service
- Production secrets are stored in managed secret stores and are never committed to source control
5. Access control
- Principle of least privilege for all production console access
- End users can access only their own account data; administrative access is restricted and audited
- Sensitive credentials and bank-linking tokens are stored server-side only and are not exposed to client applications
- Periodic review of who has access to production systems and third-party consoles
- Revoke access promptly when personnel or contractors no longer need it
6. Authentication
- Consumers: Email/password with verified email; multi-factor authentication required before bank linking
- Operators: MFA required on all accounts with production access
- Sensitive actions (such as bank linking) require verified email, explicit consent, and an authenticated session with MFA where applicable
7. Encryption
- In transit: TLS 1.2+ (HTTPS) for all client-server communication
- At rest: Application data is encrypted at rest by our cloud providers using industry-standard encryption
- Payments: Card data handled by our payment processor; Budgetmend does not store full card numbers
8. Vulnerability management
We monitor dependencies and infrastructure for known vulnerabilities, prioritize remediation based on severity and exploitability, and keep platform software on supported versions. Production infrastructure is managed by established cloud providers. Personnel devices must use OS security updates and full-disk encryption.
9. Privacy and data lifecycle
- Privacy Policy: /privacy
- Data retention policy: /data-retention
- Users may delete accounts in Settings; deletion removes personal and financial data within 30 days except where law requires retention
- Bank linking requires explicit in-app consent
10. Incident response
- Contain (revoke tokens, disable affected keys)
- Assess scope and affected users
- Notify partners if consumer financial data may be impacted
- Notify affected users and regulators as required by law
- Post-incident review and documented follow-up actions
Report incidents to security@budgetmend.com immediately.
11. Policy review
This policy is reviewed at least annually and after material architecture or compliance changes. Next scheduled review: June 2027.
For additional diligence materials not published here, contact security@budgetmend.com.