Skip to content
  • Features
  • Security
  • Blog
  • About
Sign inGet started
  • Features
  • Security
  • Blog
  • About
Sign inCreate your free workspace
  1. Home
  2. Security

Security

How Rovezi protects your money data

Finance data deserves careful, unexciting engineering. This page describes what is actually in place, without the marketing gloss.

Last updated 9 October 2026

Contents

  1. Your workspace is a boundary
  2. Signing in
  3. Encryption and hosting
  4. Private documents
  5. Money you can trust
  6. Browser and app protections
  7. Sharing and assistants
  8. Backups, logs and monitoring
  9. What you can do
  10. Reporting a vulnerability

Your workspace is a boundary

Every request to the Rovezi servers is authenticated, then checked on the server against your workspace membership before any record is read or written. Another person cannot open your accounts, transactions, people, documents or search results, even with a guessed or copied address: a record from someone else's workspace answers "not found". These isolation rules are covered by automated tests that try to cross between workspaces.

The application connects to its database with a restricted role that can do only what the app needs. It cannot change or delete posted ledger entries, and it has no permission to alter the database structure.

Signing in

  • Passkeys. You can sign in with a passkey (Face ID, fingerprint, Windows Hello or a security key). Passkeys cannot be phished or reused on another site, and we only ever store the public half.
  • Passwords are stored only as slow, salted hashes, with a minimum length of 8 characters.
  • Google sign-in is available if you prefer it.
  • Sessions are kept in a secure, HttpOnly cookie that page scripts cannot read. Short-lived signed tokens (15 minutes) carry your identity to the API. You can see your active sessions and sign out the others from Settings.

Encryption and hosting

  • All traffic uses HTTPS. HTTP Strict Transport Security (HSTS) tells browsers never to connect without it.
  • The app and its servers run on Cloudflare's network; records are kept in a managed PostgreSQL database (Neon) in Singapore. Both providers encrypt stored data at rest.
  • Secrets such as database credentials and signing keys are held in the hosting platform's secret store, never in code or in this website.

Private documents

Receipts, invoices and statement files are stored in a private storage bucket that is not reachable from the public internet. After a membership check, the app hands your browser a signed link that works for a short time only. Uploads are checked for size, and the file's actual contents must match its declared type (PDF or image), so a disguised file is refused.

Money you can trust

  • Amounts are stored as exact whole numbers in the smallest unit of each currency (paise for rupees). There is no floating point, so totals never drift.
  • Every transaction posts balanced double-entry lines. The database itself refuses a batch that does not balance.
  • History is append-only. A correction is a reversal with a reason, never a silent edit, so every change stays traceable.
  • Retrying a request, for example on a flaky connection, never creates a duplicate transaction.
  • Integrity checks run every night across the ledger, claims and balances, and raise an alert if anything is out of line.

Browser and app protections

  • A strict Content Security Policy allows only our own scripts and styles, with no inline code, which blocks most script injection.
  • Pages cannot be framed by other sites (clickjacking protection), and camera, microphone, location and payment features are switched off.
  • The app and API are never indexed by search engines, and private responses are marked not to be stored in shared caches.
  • The installed app's offline copy is limited to 7 days and is wiped on sign-out. It never stores tokens, share links or documents.
  • This public website sets no cookies and loads no third-party scripts or trackers.

Sharing and assistants

  • Share links carry a long random token (256 bits), which we store only as a hash. They show a redacted view built for that one person, expire after the period you choose, can be revoked at any time, and are never sent onward in the browser's Referer header.
  • Assistant connections use OAuth 2.1 with PKCE and a consent screen you approve. A connected assistant can only queue suggestions for your review; it cannot post, edit or delete records, and it is not given balances or people. Its tokens are stored as hashes and can be revoked.

Backups, logs and monitoring

  • Database backups are encrypted, and restoring them is rehearsed and verified: every table, migration and ledger check must match the original.
  • Logs record what happened and when, using opaque IDs. They are designed to leave out amounts, names, notes and document contents.
  • Database schema changes are versioned and checksum-verified before they are applied.

What you can do

  • Add a passkey in Settings, or use a long, unique password with a password manager.
  • Lock any phone or computer that has the installed app, and sign out on shared devices.
  • Do not store card numbers, CVV codes, PINs, OTPs or bank passwords anywhere in Rovezi. It never needs them.
  • Send share links privately to the right person, and revoke them when they are no longer needed.
  • Rovezi will never ask for your password, sign-in code or bank details by email, phone or message.

Reporting a vulnerability

If you believe you have found a security issue in Rovezi, please tell us privately atsecurity@mail.rovezi.tech rather than publishing it. Include the steps to reproduce it, the address or feature affected and what an attacker could do. Our contact details are also published insecurity.txt.

Our promise: we will acknowledge your report within 3 working days, keep you updated, fix confirmed issues as a priority and credit you if you wish. We will not take legal action against good-faith research that follows these rules.

Please test only against your own account and synthetic data. Do not access, change or delete other people's data, do not run denial-of-service or spam tests, do not use social engineering, and give us reasonable time to fix an issue before disclosing it. Rovezi has no paid bug bounty during early access.

Related

  • Privacy policy
  • Cookie and storage policy
  • Contact

A private finance workspace for people, households and small projects in India.

support@mail.rovezi.techMade in Jaipur, India

Product

  • Features
  • Security
  • FAQ

Company

  • About
  • Blog
  • Contact

Legal

  • Terms of service
  • Privacy policy
  • Cookie policy
  • Disclaimer

© 2026 Rovezi. Illustrations use fictitious data.

RSSllms.txt