WattleFolio

Security information

How customer financial information is protected and how to report a concern.

Return to portalPrivacy Policy

Controls in this release

  • The public demonstration uses a fictional in-memory plan and does not authenticate, read customer data, connect Outlook or save visitor inputs.
  • Mandatory authenticator-app multi-factor authentication before database access.
  • 15-minute privacy lock and eight-hour working-session limit. On a private browser, a user may choose to keep the verified AAL2 session for up to 30 days; the authenticator code and TOTP secret are never stored.
  • Explicit sign-out, password changes and account deletion forget the remembered device.
  • Exports, Outlook access and account deletion require a recent MFA check.
  • Supabase row-level security scoped to the authenticated household and AAL2 sessions.
  • HTTPS delivery and restrictive browser content security policies; worker-handled routes also apply additional security response headers.
  • Browser-only PDF parsing, file size/page limits and approval before imported records are saved.
  • Explicit Outlook disconnection and local Microsoft token cleanup on portal sign-out, timeout or account deletion.
  • Password-confirmed account deletion and documented incident/NDB response procedures.

Report a security or privacy concern

Email . Do not include passwords, access tokens, bank details or a user's complete household financial dataset. Include a short description, affected URL, time observed and safe reproduction steps.

What happens next

The operator will acknowledge the report, preserve evidence, contain the issue and assess potential harm under the incident and Notifiable Data Breaches response plan. Reports made in good faith will be handled responsibly.

Operator: