Legal · /security

Security

Last updated · July 2026

The most important security decision was made on day one: Monilibrium never touches your bank. No credentials, no account numbers, no money movement — there’s structurally less to steal.

Signing in

Authentication is Google OAuth only. We never see or store a password, and there’s no password database to breach.

Your data in transit and at rest

All traffic is encrypted with TLS; stored data is encrypted at rest on AWS infrastructure. Backups are encrypted too.

Operational safeguards

  • Rate limiting and abuse protection on all endpoints.
  • Least-privilege access internally — systems and people see only what they must.
  • Continuous error and audit monitoring.

Found something?

A dedicated security contact is coming as Monilibrium leaves beta. Until then, this page is kept current with how the service protects your data.