Skip to content
Trove
Security

Your money belongs to you.
So does your data.

Trove is in early testing, built by one person. Here is a plain account of what protects your data today and, just as importantly, what isn't in place yet. Nothing on this page is aspirational.

Encryption

HTTPS everywhere, with HSTS preload. Data at rest is encrypted by Supabase's managed Postgres and by Supabase Storage for uploaded receipts.

We never touch your bank

Trove has no bank connection at all. There is no Plaid integration, no credentials, no tokens. Everything in the app is data you typed or imported yourself.

Authentication

Email and password or Google OAuth, both handled by Supabase Auth. Passwords are hashed by Supabase and never reach Trove. Two-factor authentication is not available yet.

Data isolation

Postgres row-level security on every table, so a query can only ever return your own rows. Receipts live in a private bucket scoped to your user id and are served through short-lived signed URLs.

Monitoring

Server logs and an in-app audit trail of every write. A /api/health endpoint reports database reachability. There is no third-party error-tracking or analytics vendor, and no formal uptime monitoring or on-call rotation yet.

Compliance

Trove is not SOC 2 audited and no audit is currently underway. You can export everything you've stored and delete your account permanently from Settings at any time.

What isn't here yet

Being straight about the gaps is part of the point of a testing phase:

  • No two-factor authentication.
  • No third-party security audit or penetration test.
  • No formal uptime or incident-response commitment. If something breaks at 2am, it stays broken until I wake up.
  • No bug-bounty programme.

Treat Trove the way you'd treat any early product: useful for seeing your spending clearly, not a system of record.

Responsible disclosure

If you find a vulnerability, email security@trove.cool. I read it personally and will reply as quickly as I reasonably can. I'm not going to promise a response time I can't guarantee. Please give me a chance to fix an issue before publishing it. There's no bounty, but I'll credit you on release if you'd like.