DueSimple

Security without theatre

Trust should be visible, not implied.

Before the technical language, the practical boundaries are simple: your plan belongs to your account, banking credentials are never requested, and DueSimple cannot move your money.

Six safeguards

The controls around your plan

Each layer states the practical boundary first. Open the disclosure for the implementation detail.

  1. Built into the product

    Only you should enter your plan

    Your account requires verified access, supports password recovery, and can add an authenticator-app second step.

    How this works

    Verified email flows, secure sessions, password recovery, optional TOTP MFA, and recent-authentication checks form the account boundary.

  2. Built into the product

    Powerful credentials stay off your device

    The browser receives only the access needed for your signed-in session—not the credentials that administer the service.

    How this works

    Service credentials stay server-only. Authenticated operations validate the user, workspace, environment, and allowed action before financial data is touched.

  3. Enforced control

    Your plan is separated from every other plan

    A signed-in account can reach its own workspace, while the database independently enforces the same ownership boundary.

    How this works

    Row Level Security and server authorization independently limit each account to its workspace. Two-user adversarial tests exercise that boundary.

  4. Built into the product

    Financial details stay out of operational logs

    Errors can be investigated without copying household names, amounts, notes, emails, imported rows, credentials, or tokens into diagnostics.

    How this works

    Logging and error-reporting paths retain privacy-filtered request context and identifiers while excluding financial payloads and secrets.

  5. Operational practice

    You can export or request deletion

    Private exports and sensitive-action checks give you a deliberate path to retrieve or remove account data.

    How this works

    Account deletion, backup recovery, retention, and purge procedures remain operational responsibilities that must be maintained and verified.

  6. Product boundary

    DueSimple plans; it does not bank

    It cannot connect to your bank, hold money, monitor transactions, or initiate a payment.

    How this works

    Planned payments and contributions do not change real balances until the user explicitly confirms completion.

Sensitive information

Keep unnecessary secrets out.

Never enter online-banking passwords, full card or account numbers, authentication codes, security answers, government identification numbers, tax identifiers, or information that is not needed for a planning record.

Explicit boundaries

What we do not claim

No certification claim
DueSimple is not currently claiming a security certification, regulatory approval, or perfect security.
No perfect-security claim
Testing and monitoring reduce risk, but no online service can eliminate every risk.
No silent guarantee
Security controls are maintained and tested as the product evolves; they are not a substitute for a strong password and protected device.

Fictional data only

Explore without sharing financial information.

The guided demo uses one fixed fictional household and does not accept personal financial information.