Skip to content

Security

Security and reporting a vulnerability

How to tell us about a problem, what we will do, and how your data is protected.

Last updated 29 September 2026.

1.Reporting a vulnerability

WhereDidItGo handles bank data and household finances, so a security report is a priority for us, not a queue item. If you have found a vulnerability, email [email protected]. Please include what you found and why it is a vulnerability rather than unexpected behaviour, steps to reproduce it or a proof of concept, and the impact you would expect on a real household’s data.

Please do not post it publicly, or open a public issue, before we have had the chance to fix it.

2.How to test, and what we promise

  • Test only against your own account and data. Do not read, change or delete anyone else’s data. If a bug lets you see another household’s data, stop, and tell us what you saw without keeping or sharing it.
  • No denial of service, no spam, no social engineering of our staff or providers, no physical attacks.
  • Do not test our providers’ systems (your bank, Salt Edge, Stripe, Google, Apple).

If you follow these rules and act in good faith, we will not take legal action against you and we will work with you to understand and fix the problem. We do not run a paid bug bounty, but we will credit you, by name, by pseudonym or not at all as you prefer, once a fix ships.

3.What to expect from us

How quickly we respond to a security report
StepWhen
We acknowledge your reportWithin 2 business days
We tell you what we think of it: severity, and whether we accept itWithin 5 business days
A confirmed critical or high finding is fixedAs a priority over feature work

Severity follows plain impact. Anything that reads or writes another household’s money or bank data, or bypasses authentication, is critical. A problem confined to one account with no reach into anyone else’s is lower, but still real.

4.How your data is protected

  • Each household’s data is separated inside the database itself, in addition to our code checking it.
  • There are no passwords. Sign-in is by passkey, Google or Apple, or a single-use emailed link or code, with an optional second step.
  • Sensitive actions, such as removing a member or deleting an account, ask you to confirm it is you again.
  • Every sign-in, and every change made in a household, is logged, and our logs cannot be edited by the application.
  • Bank access is read-only, and we never hold your bank login.
  • Dependencies are audited on every change, and secrets are scanned for.

For the data we hold and how long, see the Privacy Policy.