Security at Checkpoint
Your financial information deserves serious protection. These are the safeguards built into Checkpoint today.
Your data
- Encrypted in transit: every connection to Checkpoint uses HTTPS, with HTTP Strict Transport Security.
- Encrypted at rest: uploaded documents and bank connection tokens are encrypted by Checkpoint before they are stored, on top of the storage provider's encryption.
- Isolated per account: every request is checked so you can only ever reach your own information. Automated tests verify this on every change.
- No bank passwords: account linking goes through Plaid; Checkpoint never sees or stores your bank login.
Your account
- Passwords are stored only as salted scrypt hashes and screened against common choices.
- Repeated sign-in and password-reset attempts are rate-limited.
- Changing your password, or choosing "sign out everywhere", ends every other session.
- Password reset links work once and expire after an hour.
- Security events such as sign-ins and data exports are logged.
How we operate
- Access to production systems is limited to the people who run Checkpoint and requires multi-factor authentication.
- All code changes are version-controlled and pass automated security and correctness tests before release.
- We follow written information security, access control, and data retention and disposal policies, reviewed at least yearly.
- If an incident affects your information, we will contain it and notify you promptly.
You're in control
Download all of your data at any time, disconnect linked accounts, or delete your account and everything in it from Settings. See our privacy policy for details.
Report a vulnerability
If you believe you've found a security issue, please email hello@checkpointfinance.app with "Security report" in the subject. We'll acknowledge it within 2 business days. Please don't access other people's data or disrupt the service while testing.