Last reviewed: May 2026
Security
Finding Wealth is built to protect your financial data. This page describes the controls we have in place, what we genuinely do, and where our current limitations are. We do not make claims we cannot back up.
How we protect your bank connections
Bank account connections are powered by Plaid Technologies, Inc., a regulated financial data platform. When you connect an account:
Encryption and data protection
Authentication and access control
Browser and network security
Data deletion and account removal
You can delete your Finding Wealth account at any time from Account Center → Settings → Delete Account. Deletion:
For a manual data deletion request, email privacy@findingwealth.ca.
Error monitoring
We use Sentry to capture runtime errors and performance issues. Sentry is configured to scrub cookies, authentication headers, and personally identifiable information from error payloads before transmission. Error data is used solely for diagnosing and fixing software issues.
What we do not have (honest disclosure)
We believe you deserve an accurate picture of our security maturity. The following are not currently in place:
- SOC 2 or ISO 27001 certification — we apply many of these practices but are not certified.
- Mandatory MFA — two-factor authentication is deployed and user-available; it is not enforced at login for all users.
- Third-party penetration testing — not yet conducted.
- A dedicated security team — security is reviewed by our engineers.
We are committed to improving our security posture as the platform grows.
Reporting a vulnerability
If you discover a security issue, please report it responsibly to privacy@findingwealth.ca before public disclosure. Include a description of the issue and steps to reproduce. We will acknowledge receipt within 5 business days and keep you informed of our progress.
Subprocessors
Finding Wealth uses the following third-party services that may process your data:
| Subprocessor | Purpose |
|---|---|
| Supabase | Database, authentication, storage |
| Vercel | Hosting, CDN, edge network |
| Plaid Technologies, Inc. | Bank account connectivity (read-only) |
| Stripe, Inc. | Payment processing |
| PayPal Holdings, Inc. | Payment processing |
| Anthropic, PBC | AI coach (Horizon AI) |
| Sentry | Error monitoring |
| Google LLC | Optional OAuth sign-in |
Questions? Email privacy@findingwealth.ca