Security

Your Financial Data,
Protected.

Waypoint Budget uses bank-level encryption, trusted security partners, and strict access controls to keep your financial information safe. We never see your bank passwords, and we never sell your data.

Security at a Glance

Three pillars that protect every piece of your financial data

Bank-Level Encryption

All data is encrypted with SSL/TLS in transit and encrypted at rest. The same standards used by major financial institutions.

Zero Credential Storage

We never see or store your bank passwords. Bank connections go through Plaid, and you authenticate directly with your bank.

Secure Infrastructure

Hosted on Vercel with automatic backups, DDoS protection, and edge network delivery worldwide.

Plaid

How Bank Sync Works

Powered by Plaid, the same service used by Venmo, Coinbase, and thousands of financial apps

Plaid Is the Intermediary

When you connect a bank, you log in through Plaid's secure portal, not through Waypoint Budget. Your credentials go directly to Plaid, and we never see them.

Read-Only Access

Waypoint Budget can only read transaction data. No one, including Plaid, can move money, make transfers, or modify your accounts.

Trusted by 12,000+ Institutions

Plaid connects to over 12,000 financial institutions across the US and Canada. It undergoes regular security audits and maintains SOC 2 Type II compliance.

Revoke Access Anytime

You can disconnect your bank accounts from Waypoint Budget at any time. You can also revoke Plaid's access directly through your bank or Plaid's portal.

Authentication & Payments

Industry-leading partners handle your login and payment security

Clerk

Authentication by Clerk

Clerk is an enterprise-grade authentication platform that handles your login securely. It is SOC 2 Type II compliant and supports multi-factor authentication.

  • SOC 2 Type II compliant
  • Multi-factor authentication support
  • Session management and device tracking
Stripe

Payments by Stripe

Stripe handles all payment processing. They are PCI DSS Level 1 certified, the highest level of security certification in the payments industry.

  • PCI DSS Level 1 certified
  • We never see or store your card number
  • Encrypted payment sessions

Data Privacy

Your data belongs to you. Period.

We Never Sell Your Data

Your financial data is never sold, shared with advertisers, or used for marketing purposes. We make money from subscriptions, not your data.

Export Your Data

You can export all your data at any time. Your budgets, transactions, and financial history are always accessible to you.

Delete Everything Anytime

You can delete your account and all associated data at any time. Once deleted, your data is permanently removed from our systems.

Full Privacy Policy

Read our complete privacy policy for details on how we collect, use, and protect your information. View privacy policy

Infrastructure Security

Built on trusted, modern infrastructure from the ground up

Hosted on Vercel

Waypoint Budget runs on Vercel's globally distributed infrastructure with automatic scaling, DDoS protection, and edge network delivery.

Encrypted PostgreSQL Database

All data is stored in PostgreSQL with encryption at rest. Regular automated backups ensure your data is never lost.

Regular Security Updates

Dependencies and infrastructure are kept up to date with the latest security patches. We monitor for vulnerabilities continuously.

HTTPS Everywhere

Every connection to Waypoint Budget is encrypted with HTTPS. We enforce strict transport security headers to prevent downgrade attacks.

Security FAQ

Can Waypoint Budget access my bank account?
No. Waypoint Budget connects to your bank through Plaid with read-only access. We can only view transaction data. No one can move money, make transfers, or modify your accounts through Waypoint Budget. You can revoke access at any time from your account settings or directly through Plaid.
What data does Waypoint Budget store?
Waypoint Budget stores your transaction data, budget categories, savings goals, and account preferences. We never store your bank passwords, login credentials, or credit card numbers. Authentication is handled by Clerk, and payments are processed by Stripe. Neither passes sensitive credentials through our systems.
Can I delete my data?
Yes. You can delete your account and all associated data at any time from your account settings. When you delete your account, all your personal data, transactions, budgets, and goals are permanently removed from our systems. This action is irreversible.
Is my payment information secure?
Yes. All payment processing is handled by Stripe, which is PCI DSS Level 1 certified, the highest level of payment security certification in the industry. Waypoint Budget never sees or stores your credit card number. Your payment details go directly to Stripe through their encrypted payment forms.
What happens if there's a data breach?
In the unlikely event of a data breach, we will notify affected users promptly and take immediate corrective action. Because we do not store bank passwords or credit card numbers, the risk of financial credential exposure is significantly reduced.

Start Budgeting with Confidence

Your financial data is protected by bank-level encryption, trusted security partners, and strict privacy controls. Free to start, no credit card required.

No credit card required · Bank-level encryption · Delete your data anytime