FinFuse

Security

Last updated September 27, 2026

FinFuse is built so that as little as possible can go wrong with your account or your information. This page describes the protections in place today. It is part of, and should be read with, our Privacy Policy.

1. Account protection

FinFuse operates its own sign-in. No third-party identity service sits between you and your account.

Passwords are never stored as written. Each password is kept only as a one-way scrypt hash with its own random salt, so it cannot be read back, including by us.

Repeated failed sign-in attempts are rate-limited, by network address and by email address, to prevent guessing.

2. Sessions

When you sign in, FinFuse sets a signed session cookie. It is marked Secure and HttpOnly, so it travels only over encrypted connections and cannot be read by scripts in your browser.

Your session is checked against your account on every request before anything is shown.

Sessions end after 30 days of inactivity. Changing your password, or choosing Sign out everywhere in Settings, ends every other session at once.

3. Password resets

A password reset link is sent only to the email address on the account. It can be used once and expires one hour after it is issued. Only a hash of each link is stored.

4. Encryption in transit

FinFuse is served only over HTTPS, with strict transport security, so information you send us is encrypted on its way.

5. What we never hold

6. Your controls

You can download everything you have entered, or delete it, from Settings at any time.

7. Reporting a security issue

If you believe you have found a security issue, please contact us through our contact page. Please give us a reasonable chance to fix it before disclosing it publicly.