Legal · /security
Security
Last updated · July 2026
The most important security decision was made on day one: Monilibrium never touches your bank. No credentials, no account numbers, no money movement — there’s structurally less to steal.
Signing in
Authentication is Google OAuth only. We never see or store a password, and there’s no password database to breach.
Your data in transit and at rest
All traffic is encrypted with TLS; stored data is encrypted at rest on AWS infrastructure. Backups are encrypted too.
Operational safeguards
- Rate limiting and abuse protection on all endpoints.
- Least-privilege access internally — systems and people see only what they must.
- Continuous error and audit monitoring.
Found something?
A dedicated security contact is coming as Monilibrium leaves beta. Until then, this page is kept current with how the service protects your data.