Chapter 03 · Security
What we hold, and how we hold it.
Every balance in Twiggybank is practice money, which keeps the security surface small. There are no funds to move and no card numbers to lose. The data we do hold is a small family record and the names attached to it, and we treat it with the care family records deserve.
We do hold
- Family
- A family name, a currency, a time zone, and your chosen configuration (allowance schedules and the saving growth rate).
- People
- An email address for each Adult. A display name, an optional birthday, and a chosen color for each kid.
- Ledger
- Every money event your family records: paydays, saving growth, spend requests, fixes. Once it happens it stays in the record as it was. Sized in whole cents of your family currency.
- Auth metadata
- Session tokens and password hashes managed by our auth provider. Standard browser cookies for keeping you signed in.
We do not hold
- Card numbers
- We never see or touch a card. No PCI scope.
- Bank accounts
- No ACH and no balances at any real institution.
- Real money
- Every figure is practice money. There are no real balances.
- Behavioral data
- We build no advertising profile and run no third-party trackers. We sell nothing we collect.
- Photos of children
- Only display names. No image uploads of kids in v1.
How we protect it
Boring is the goal.
Twiggybank runs on well-trodden infrastructure. We have not invented our own cryptography or our own authentication. The less novelty in the stack, the more the security guarantees come from the people who do this for a living.
- Hosting
- The web app is deployed on Vercel; the database is managed Postgres hosted by Supabase. Both encrypt data at rest by default and serve all traffic over TLS.
- Isolation between families
- Postgres row-level security policies tie every read and write to your family ID. There is no API path that can ask for another family's data. The database refuses before the app ever sees the request.
- Authentication
- Passwords are never stored in plaintext; auth is handled by Supabase Auth, which uses industry-standard hashing and short-lived session tokens.
- Transport
- HTTPS everywhere. Cookies are marked secure and HttpOnly. No mixed-content surfaces.
- Ledger immutability
- Posted records cannot be edited from any client. A correction adds a new, linked record that undoes the original, and both stay visible. Tampering would require database access we do not give to ourselves casually.
- Least privilege
- The service key that can bypass row-level security never ships to the browser or mobile app. It lives only on the server, scoped to specific operations.
Kids
The smaller set.
We collect the minimum from children: a display name, an optional birthday, a chosen color, and the money events an Adult or the kid posts to the family record. We hold no contact information for a kid and no advertising data.
What we do not offer yet
We’ll get to it.
We are a small project. We do not yet offer two-factor authentication, hardware-key sign-in, audit-log export to Adults, or SOC 2 certification. Each is on the list, and none is shipped.
Reporting an issue
We want to hear it.
If you’ve found something that looks like a vulnerability, email security@twiggybank.com. Please give us a chance to look at it before publishing details. We’ll respond within a few days and credit you, if you’d like the credit.