Security at MoneyKit
Our mission at MoneyKit is to make Internet Money Magic. We link your financial accounts to your Internet applications so you can you track your money, increase your savings and investment performance, and increase your financial leverage. To make this happen safely and securely, MoneyKit uses best-in-class cryptographically secure systems within an actively audited, logged, monitored, and access-controlled framework to keep your data safe.
Data Security
MoneyKit encrypts data at rest and in transit for all of our customers. We use tools like Amazon Web Service’s Key Management System (KMS) to manage encryption keys using hardware security modules for maximum security in line with industry best practices.
Application Security
MoneyKit regularly engages some of the industry’s best application security experts for third-party penetration tests. Our penetration testers evaluate the source code, running application, and the deployed environment.
MoneyKit also uses high-quality static analysis tooling provided by GitHub Advanced Security, such as Dependabot, to secure our product at every step of the development process.
Infrastructure Security
MoneyKit uses Amazon Web Services to host our application. We make full use of the security products embedded within the AWS ecosystem, including KMS, GuardDuty, and Inspector.
In addition, we deploy our application using containers run on AWS managed services, meaning we typically do not manage servers or EC2 instances in production.
Bug Bounty Program
MoneyKit encourages members of the security community to find vulnerabilities with our systems. Please see our Bug Bounty Program page for details, or write us at security@moneykit.com.
Trusted and Trustworthy
MoneyKit is certified SOC 2 compliant, the industry standard for organizational controls relevant to security, availability, processing integrity, confidentiality, and privacy. You may request access to our most recent SOC 2 report via email to security@moneykit.com.
MoneyKit uses Thoropass for SOC2 auditing and compliance.