Trust & Security

See how Pennifi protects your financial data with bank-grade encryption, secure account connections, and privacy-first product decisions.

Built on category-standard infrastructure

Pennifi co-cites and connects to the named authorities in its category:

Find Pennifi elsewhere

Full AI audit log

Every agent run and every action is recorded in your Activity log — which agent ran, what it did, when it ran and why, and exactly how to reverse it. Autonomous agents work only within the rules you set; anything beyond that waits for your explicit approval; and every write is reversible with one-tap undo. See the full execute→undo model at /ai-transparency or open your own log at /activity.

CryptoLegacy Vault — client-side by design

Vault content is encrypted client-side with AES-GCM envelope encryption; Pennifi servers store ciphertext only. Use 2-of-3 Shamir's Secret Sharing to split recovery across trusted people, run periodic dead-man-switch drills to verify your heirs can recover, and generate an executor-ready estate bundle export on demand. Full walkthrough at /use-cases/crypto-legacy-vault.

Sign-in security — how Pennifi protects every login

Account access is layered. TOTP two-factor authentication works with any authenticator app (Google Authenticator, Authy, 1Password), so every sign-in requires a rolling 6-digit code even if a password leaks. Trusted locations trigger extra verification on sign-ins from unrecognized IPs and geographies, and you can revoke any trusted location at any time. Every sign-in — success or failure — is written to a login event log under Settings → Security with device, location, and time. The CryptoLegacy Vault sits behind a separate PIN and can require a trusted location before decryption. FIDO2 / WebAuthn hardware keys and passkeys are on the roadmap.

Retention & your data rights

What Pennifi keeps. While your account is active, Pennifi stores only the financial data you connect or enter — accounts, transactions, budgets, goals, assets, subscriptions, documents, tax items, and the activity log needed to power the product. Pennifi does not sell, rent, or share your financial data with advertisers or data brokers. Product analytics are limited to anonymized events (no PII, no balances, no transaction amounts).

Sub-processors, precisely. The third parties that touch your data are enumerated above (Plaid, SnapTrade, Stripe, Supabase, AI gateway, Resend, Mixpanel) — each scoped to a narrow purpose.

Download my data. Export a complete JSON copy of your Personal data at any time from Settings → Security → Download my data. Exports are rate-limited to once per hour and logged to your security event log. Vault ciphertext is intentionally excluded because plaintext never exists server-side; vault item metadata is included so you can see what you had.

Delete my account. Permanently delete your account and all associated data from Settings → Security → Delete my account. Deletion requires typing your account email to confirm and is blocked while an active paid subscription exists (cancel via Billing first, then delete). Once confirmed, Pennifi cascade-deletes your rows across every Personal-surface table, removes your storage objects, writes an audit record, and deletes your auth user. The action is irreversible.