Encrypted before durable storage
Sensitive item details are encrypted on your device before they are durably stored. Unyt stores ciphertext, access metadata, key grants, and the minimum routing information needed to operate the product.
Unyt is built for the person trusted with a family's financial context. That means clear boundaries: what the app needs to operate stays separate from the bank accounts, policies, notes, files, and contacts only you and approved family members should read.
Sensitive item details are encrypted on your device before they are durably stored. Unyt stores ciphertext, access metadata, key grants, and the minimum routing information needed to operate the product.
Your master password unlocks encrypted key material on trusted devices. We do not store it, and we cannot use support access to read encrypted account numbers, policy IDs, notes, or document contents.
Every shared item carries per-recipient key grants. Your mother, spouse, or any approved family member can decrypt only the items you share with them, without knowing your master password.
You can change access later. When encrypted access is removed, the owner client rotates that item key and re-grants access only to the remaining approved members.
All traffic is served over HTTPS with HSTS. Client-side encryption protects sensitive payloads before durable storage; TLS remains required for every request.
Production storage is India-region first, in line with Indian data-localisation expectations. Encrypted payloads and durable documents remain ciphertext at rest.
We do not sell/advertise your data. We do not use your account contents, documents, or notes to train AI models. Document parsing happens in scoped, user-triggered flows.
Sessions expire on inactivity. Sensitive actions such as family invitation acceptance, account deletion, recovery, and encryption changes require additional confirmation.
We are working toward third-party security certification. We will publish dated attestations here as they are completed — we will not list certifications we do not yet hold.
Found a vulnerability? Email security@unyt.money. Our security.txt is published at /.well-known/security.txt. We acknowledge reports within five business days.
We take responsible disclosure seriously. Reach us at security@unyt.money - we acknowledge reports within five business days.