Security Shield

Secure by Design.
Protected by Default.

We don't just "add" security. We built our entire architecture around it. From HttpOnly cookies to strict CSP headers, your data is locked down.

SOC 2 Type II ISO 27001 GDPR
🍪

HttpOnly Cookies

Tokens are stored where JavaScript can't reach them. This eliminates an entire class of XSS attacks.

Set-Cookie: HttpOnly; Secure
🧱

Strict CSP

Our Content Security Policy blocks all unauthorized scripts, styles, and connections.

default-src 'self'; script-src ...
🔑

Short-Lived Tokens

Access tokens expire in 15 minutes. Refresh tokens rotate automatically. Risk window is minimized.

exp: 1713450900 (15m)

Infrastructure Protection

Your data is encrypted at every stage.

🔒

Encryption in Transit

All traffic is encrypted via TLS 1.3. We force HTTPS and use HSTS headers to prevent downgrade attacks.

💾

Encryption at Rest

Database volumes and S3 buckets are encrypted using AES-256. Keys are managed via AWS KMS.

🛡️

WAF & DDoS Protection

Cloudflare Enterprise WAF filters malicious traffic before it hits our servers.

🕵️

Intrusion Detection

Automated scanning for anomalous behavior and unauthorized access attempts.

Flexible Authentication

Choose the login method that works best for your team. All methods support 2FA for enhanced security.

📧

Email & Password

Traditional authentication with mandatory two-factor authentication for all accounts.

🔵

Google Workspace

Sign in with your Google account. Perfect for teams already using Google Workspace.

🟦

Microsoft 365

Authenticate with Microsoft. Ideal for organizations using Azure AD.

New
🔷

Xero Login

Sign in with Xero. Built specifically for accounting professionals.

Enterprise SSO/SAML: Need Azure AD, Okta, or OneLogin integration? Enterprise plans include full SAML support. Contact sales

Two-Factor Authentication

Mandatory 2FA for all accounts. Add an extra layer of security beyond passwords. Compatible with all major authenticator apps and hardware keys.

  • TOTP (Google Authenticator, Authy, 1Password)
  • WebAuthn / YubiKey Support
  • Emergency Backup Codes
  • SMS Fallback (optional)
Always-On Protection: 2FA is required for all sensitive operations including login, API key management, and organization settings changes.
Authenticator
Coincile (admin@fund.com)
592 104
Google (personal)
*** ***
Security Scorecard
XSS Protection A+
CSRF Prevention A+
TLS/SSL Config A+
Headers A+

Trust your financial data to the experts.

Get Secure Access