débutFin

Security center

Trust is a chain of proved boundaries.

Security claims here describe implemented controls, not an assurance certification. Release evidence and unresolved gates remain separate from marketing language.

Effective July 30, 2026 · Last updated July 30, 2026

Data boundaries

  • Authenticated records use owner-scoped row-level database policies and least-privilege service operations.
  • Original documents and uploaded backgrounds use private object storage with ownership, type, size, and deletion controls.
  • Bank access tokens and operational cursors are server-only and unavailable to browser roles.
  • Exports omit session credentials and provider tokens; destructive actions require preview, confirmation, and audit evidence.

Application and integration controls

Security headers restrict framing, content types, permissions, cross-origin resources, and script execution. Authentication routes use bot protection when configured. Durable jobs use leases, retries, idempotency, and recovery rather than assuming an edge process will remain alive. Provider success is not accepted until the expected downstream state is persisted and reconciled.

Financial and AI safety

Material calculations use versioned deterministic engines with integer-cent arithmetic and explicit missing inputs. Advisor output is schema-validated, source-traced, proposal-only, and disabled when cost or provider gates are not configured. The model is not permitted to invent authoritative balances, execute financial actions, or mark an outcome verified.

Responsible disclosure

If you believe you found a vulnerability, email contact@debutfin.com with “Security report” in the subject. Include the affected route, reproducible steps, impact, and a safe way to contact you. Do not access another person's data, degrade service, use social engineering, or publish sensitive details before there is a reasonable opportunity to investigate.

Independent assurance status

Automated tests, database isolation checks, dependency audits, and recovery drills are release inputs, not substitutes for independent penetration testing or a formal SOC 2, ISO 27001, PCI, or similar certification. débutFin will not display those marks unless the applicable audit and authorization have actually been completed.