Security

Security is not a setting. It is the shape of the product.

Unyt is built for the person trusted with a family's financial context. That means clear boundaries: what the app needs to operate stays separate from the bank accounts, policies, notes, files, and contacts only you and approved family members should read.

Security that makes sharing easier to trust

visibility_lock

Encrypted before durable storage

Sensitive item details are encrypted on your device before they are durably stored. Unyt stores ciphertext, access metadata, key grants, and the minimum routing information needed to operate the product.

vpn_key

Your master password is not ours

Your master password unlocks encrypted key material on trusted devices. We do not store it, and we cannot use support access to read encrypted account numbers, policy IDs, notes, or document contents.

group

Family sharing without a family password

Every shared item carries per-recipient key grants. Your mother, spouse, or any approved family member can decrypt only the items you share with them, without knowing your master password.

visibility

Access changes stay smooth

You can change access later. When encrypted access is removed, the owner client rotates that item key and re-grants access only to the remaining approved members.

What this means in plain English

  • check_circleWe can show your list, enforce access, sync devices, and apply plan limits without needing to read the private fields inside each item.
  • check_circleApproved family members receive their own encrypted access to shared items. You never have to send them your master password.
  • check_circleDurable document files are encrypted before storage. AI extraction uses an explicit temporary processing copy only when you start that flow.
  • check_circleIf you lose both your master password and recovery key, encrypted details are unrecoverable by design.

Operating practices

  • shield

    Transport security

    All traffic is served over HTTPS with HSTS. Client-side encryption protects sensitive payloads before durable storage; TLS remains required for every request.

  • storage

    Data residency

    Production storage is India-region first, in line with Indian data-localisation expectations. Encrypted payloads and durable documents remain ciphertext at rest.

  • no_accounts

    No data sales, no model training

    We do not sell/advertise your data. We do not use your account contents, documents, or notes to train AI models. Document parsing happens in scoped, user-triggered flows.

  • history

    Auth and session controls

    Sessions expire on inactivity. Sensitive actions such as family invitation acceptance, account deletion, recovery, and encryption changes require additional confirmation.

  • science

    Independent audits

    We are working toward third-party security certification. We will publish dated attestations here as they are completed — we will not list certifications we do not yet hold.

  • mail

    Responsible disclosure

    Found a vulnerability? Email security@unyt.money. Our security.txt is published at /.well-known/security.txt. We acknowledge reports within five business days.

What we will not do

  • We will not sell your data to anyone.
  • We will not train AI models on your account contents, documents, or notes.
  • We will not show third-party advertising inside Unyt.
  • We will not require you to share more than you want to with your family.
  • We will not ask for your master password or recovery key.
  • We will not claim certifications we do not hold.

Report a security issue

We take responsible disclosure seriously. Reach us at security@unyt.money - we acknowledge reports within five business days.