Security & Compliance

Last updated: March 16, 2026

No Guilt Money is committed to protecting the security of your financial data. This page describes our security practices, architecture, and compliance posture.

Security Status

TLS 1.2+ encryption in transit
✓ Enforced
Database SSL connections required
✓ Enforced
Passwords hashed with bcrypt
✓ Cost factor 12
JWT authentication on all API endpoints
✓ Active
TOTP two-factor authentication
✓ Available
Rate limiting on auth endpoints
✓ Active
Security headers (HSTS, CSP, X-Frame-Options)
✓ Enforced via CloudFront
Audit logging on all sensitive actions
✓ Active
Plaid integration (read-only bank data)
✓ Sandbox

Information Security Policy

Scope

This policy applies to all systems, personnel, and third-party services involved in the operation of No Guilt Money, including AWS infrastructure, database systems, and external API integrations.

Access Control

Zero Trust Architecture

Data Classification

Vulnerability Management

Dependency Scanning

EOL Software Policy

Patching SLA

SeverityCVSS ScorePatch SLA
Critical9.0–10.024 hours
High7.0–8.97 days
Medium4.0–6.930 days
Low0.1–3.990 days

Identity & Access Management

Access Reviews

User accounts and API integrations are reviewed quarterly. Inactive accounts (no login in 90 days) are flagged for review and may be deactivated.

Incident Response

Detection

Response

Consumer-Facing Application Security

Responsible Disclosure

If you discover a security vulnerability in No Guilt Money, please report it to security@noguilt.money. We will acknowledge receipt within 24 hours and work to address valid vulnerabilities promptly.