Security
What we actually do with the data.
This page lists controls that are in the product. It does not list badges we have not been audited for. In particular, we do not claim SOC 2 or an equivalent certification.
Access
The site is served over TLS. The product session is the allwr_session cookie: HttpOnly and SameSite=Lax, so a script on the page cannot read it and another site cannot attach it to a POST.
Identity goes through OpenID Connect at login.allwr.io. The browser does not keep the access token: the PHP session is the reference. Every change of data requires that session’s CSRF proof.
Bank data
The bank password is not stored. The connection happens in the aggregator’s widget. Full IBANs, balances where they travel encrypted, and refresh tokens use AES-256-GCM. The master key is not in the repository.
Application logs do not keep that data in the clear. A change of permission, consent or payment leaves a record of who did it.
Report a problem
If you find a flaw that affects data or access, write to privacy@allwr.io. Include the steps, and do not include the bank credential or a live API key. We do not run a public bounty. We do read the report and reply.