Who can see the family’s data, and how is it kept private?
Confidentiality in this business is usually asserted rather than described. What follows is the description, including the parts that are limitations.
One installation per family
Each family has its own installation, with its own store. There is no shared database holding several families, and therefore no query that could return another family’s figures by mistake. It also means a problem on one installation cannot reach another.
Who gets in
Access is by invitation only. Every user is created deliberately, with a role and a list of the pages they may see: a family member can be given the overview and nothing else, an accountant the ledgers and not the vault.
A second factor is required in addition to the password, so a stolen password is not enough on its own. Passwords are held as one-way fingerprints, which means they cannot be read back, and every action is recorded in an audit log with who did it and when.
What is never held
No banking credential of yours is stored, because none is ever asked for. The platform reads the statements the family already receives; it does not log in anywhere on your behalf. There is nothing to steal on that front, because nothing is held.
Where the data sits
The platform runs with a hosting provider, and the data sits on that provider’s infrastructure rather than on a machine in the family’s office. The provider and the territory are stated in writing before anything begins, and any change of either is notified. For a family whose own confidentiality obligations are strict, this is a question to ask of every supplier, and one worth answering precisely rather than reassuringly.
Who else has access
Two parties, and it is better said plainly than implied. The people who use the platform, as defined by the family. And whoever maintains it, whose access exists because someone has to be able to fix it. Beyond that, the hosting provider has the technical access any hosting provider has to the systems it runs. Anyone claiming a shorter list is either not counting themselves or not counting their supplier.
What is reviewed, and how
The security arrangements are reviewed periodically rather than once at the start, and the platform is built to fail closed: when something cannot be verified, access is refused rather than granted. Two practical notes, because a page like this is worth little if it only lists the good parts. Sign-in is not yet bound to a device or a network, by deliberate choice, since that binding locks out travelling users more often than it stops anyone. And no external security audit has been commissioned; if a family requires one, it can be arranged and paid for as part of the engagement.