Security

Why your household's data is safe here.

Compound started as one family's private cockpit, so it was built the way you'd want your own family's data handled. Here's exactly how, in plain language.

Encryption in transit and at rest

  • Every page and API is served over HTTPS only, with HTTP Strict Transport Security.
  • Bank, brokerage and email connection tokens are encrypted with AES-256-GCM before they are stored, using a key held only in server configuration, never in the database. A copy of the database alone can't unlock your accounts.
  • The database itself runs on Supabase, which encrypts stored data at rest.

Row-level security on every table

  • Every table has Postgres row-level security switched on. The database itself decides which rows a signed-in person may read, so a household only ever sees its own data, even if app code had a bug.
  • Server code that needs wider access (scheduled syncs, sign-in callbacks) is scoped to the household it resolves on the server, never to an id sent by the browser or phone.

Read-only access to your money

  • Banks and cards connect through Plaid for transactions, statements, loan details and account-holder identity. Compound requests no payment or transfer products.
  • Brokerages connect through SnapTrade, and Compound only calls its account, position and activity endpoints. It never places trades or moves money.

Read-only email, and only what matters

  • Gmail connects with the read-only gmail.readonly permission; Outlook with Mail.Read. Calendar access, if you turn it on, is read-only too. Compound can't send, delete, label or change anything.
  • Compound keeps the full text only of orders, shipping and returns, receipts, travel bookings and loyalty statements. For other mail, it keeps only a small record (sender, subject, date and a short preview) so it isn't fetched again, and discards the body.
  • Web page markup in emails is never stored. You can limit Compound to a single label or folder. Disconnecting deletes the stored token (and revokes it with Google for Gmail), and can delete the imported mail too.

Kid-safe roles, enforced on the server

  • Every member has a role: owner, adult or child. A child's sign-in can't read balances, transactions, holdings, fares or anyone else's purchases.
  • This is enforced by the database's own access rules, with the app's page and API checks and a role-scoped AI agent layered on top. New invitations default to the least-privileged role.

Family Locator keeps as little as possible

  • Locations are visible only to your own household, never outside it, and the household owner can switch Family Locator off for everyone.
  • For adults, only the current location is kept, overwritten each time. For children, the last 7 days of places are kept and older points are deleted automatically every day.
  • Turning the Locator off deletes the household's location data.

AI that works for you, not on you

  • Every AI model call goes through Vercel AI Gateway to Anthropic, Google, OpenAI or TypeSafe AI. We don't use your data to train models, Vercel doesn't train on gateway traffic, and Vercel lists each of these providers as not training on prompt data sent through the gateway.
  • Before mail is classified, only its sender, subject and a short preview are sent. Our AI logs keep the model's answer and a fingerprint of the prompt, not the prompt itself.
  • The Ask agent answers only from data your role is allowed to see.

Sign-in and secrets

  • Sign in with a one-time email code, a magic link, Google, or a password. Compound is invitation-only: public sign-ups are switched off.
  • API keys and service credentials live only on the server. The database's all-access key is marked server-only in code, so it can't be bundled into the web app or the iPhone app.
  • Scheduled jobs, the payments webhook and the email connection flow each authenticate themselves: a shared secret for jobs, a verified signature for payments, and a one-time, browser-bound state for email.

Backups

  • The database is backed up daily by Supabase and those backups are kept for 7 days.
  • We're adding a second, encrypted nightly copy stored off Supabase, so a single provider problem can't lose your data.

What the people running Compound can see

  • Compound is run by a small team. Like any hosted service, the operator has administrative access to the database and uses it only for support, fixing bugs and keeping syncs healthy.
  • The operator dashboard shows accounts, roles, app activity logs, and AI usage and cost. It doesn't display your balances or email.
  • Diagnostic tools can list, without storing, which messages in a connected mailbox match Compound's searches, and may show a sample of their senders and subjects. They never read message bodies, and we're limiting them to households that have opted in.

If something goes wrong

  • If we learn of a security incident affecting your data, we'll contain it, rotate any affected credentials, and tell affected households by email promptly, including what happened and what we're doing about it.
  • You can disconnect any bank or mailbox from Settings at any time, and ask us to delete your household's data.

Who we share data with

We never sell your data or share it for advertising. These service providers process it only to run Compound for you.

ProviderWhat forWhat they receive
SupabaseDatabase, sign-in and file storage (US East)All household data
VercelHosting, scheduled jobs and the AI GatewayRequests in transit; AI prompts in transit
PlaidBank, card and loan connectionsBank credentials (entered with Plaid, never seen by us), balances, transactions, statements
SnapTradeBrokerage connectionsBrokerage holdings and activity
GoogleGoogle sign-in and read-only Gmail and Calendar, if you connect them; Gemini models via the AI GatewayMail and calendar you allow; text sent for AI extraction
MicrosoftRead-only Outlook mail and calendar, if you connect themMail and calendar you allow
AnthropicClaude models via the AI GatewayText sent for AI extraction and Ask answers
OpenAIGPT models, search embeddings and text-to-speech via the AI GatewayText sent for AI extraction, search and spoken answers
TypeSafe AIJev classifier via the AI GatewayEmail sender, subject and preview; transaction descriptions
ResendService email deliveryRecipient address and message
ApplePush notifications to the iPhone appDevice token and notification text
OpenStreetMap NominatimPlace names for travel check-insRounded coordinates of a check-in

Market prices come from market-data services that receive ticker symbols only, never your account details.

Report a vulnerability

Found a security issue? Email security@galvyn.xyz with the steps to reproduce it. We'll acknowledge your report, keep you updated while we fix it, and credit you if you'd like. Please test only against your own account, don't access other people's data, and give us a reasonable time to fix the issue before sharing it. We won't pursue good-faith research that follows these rules.

Machine-readable contact: /.well-known/security.txt

More detail in our privacy policy and terms.