Security
Security and reporting a vulnerability
How to tell us about a problem, what we will do, and how your data is protected.
Last updated 29 September 2026.
1.Reporting a vulnerability
WhereDidItGo handles bank data and household finances, so a security report is a priority for us, not a queue item. If you have found a vulnerability, email [email protected]. Please include what you found and why it is a vulnerability rather than unexpected behaviour, steps to reproduce it or a proof of concept, and the impact you would expect on a real household’s data.
Please do not post it publicly, or open a public issue, before we have had the chance to fix it.
2.How to test, and what we promise
- Test only against your own account and data. Do not read, change or delete anyone else’s data. If a bug lets you see another household’s data, stop, and tell us what you saw without keeping or sharing it.
- No denial of service, no spam, no social engineering of our staff or providers, no physical attacks.
- Do not test our providers’ systems (your bank, Salt Edge, Stripe, Google, Apple).
If you follow these rules and act in good faith, we will not take legal action against you and we will work with you to understand and fix the problem. We do not run a paid bug bounty, but we will credit you, by name, by pseudonym or not at all as you prefer, once a fix ships.
3.What to expect from us
| Step | When |
|---|---|
| We acknowledge your report | Within 2 business days |
| We tell you what we think of it: severity, and whether we accept it | Within 5 business days |
| A confirmed critical or high finding is fixed | As a priority over feature work |
Severity follows plain impact. Anything that reads or writes another household’s money or bank data, or bypasses authentication, is critical. A problem confined to one account with no reach into anyone else’s is lower, but still real.
4.How your data is protected
- Each household’s data is separated inside the database itself, in addition to our code checking it.
- There are no passwords. Sign-in is by passkey, Google or Apple, or a single-use emailed link or code, with an optional second step.
- Sensitive actions, such as removing a member or deleting an account, ask you to confirm it is you again.
- Every sign-in, and every change made in a household, is logged, and our logs cannot be edited by the application.
- Bank access is read-only, and we never hold your bank login.
- Dependencies are audited on every change, and secrets are scanned for.
For the data we hold and how long, see the Privacy Policy.