Siegel Financial Siegel FinancialWealth, made clear Back to dashboard
Security

Report a security concern.

If you believe you found a vulnerability, please send enough detail for the issue to be reproduced and fixed quickly. Reports are reviewed with priority because user trust matters here.

Last updated: July 18, 2026

How to report

Email hello@siegelfinancial.org with the subject Security Report. If you can, include:

Please do not include passwords, API keys, Social Security numbers, full account numbers, or another person's private data in a report.

Safe testing rules

Good-faith reports are welcome. To keep users protected, please stay within these limits:

There is not a paid bug bounty program at this time, so no reward is promised for reports.

Current protections

Encrypted trafficThe site is served over HTTPS, with browser security headers configured through Firebase Hosting.
Private user recordsFirestore rules limit direct browser access to the signed-in user's plan. Connected financial data and billing state are server-only.
Managed loginFirebase Authentication handles account login, password reset, and session management.
Abuse protectionFirebase App Check with reCAPTCHA helps limit automated abuse of backend services from unsupported origins.
Protected connection tokensPlaid access tokens are encrypted with authenticated AES-256-GCM encryption before storage and are never returned to the browser.
Verified service eventsPlaid and Stripe webhook signatures are checked before connection or subscription events are processed.
Credential boundariesInstitution credentials are entered only inside Plaid Link and payment details only on Stripe Checkout. Siegel Financial does not receive or store either.
Restricted browser accessSecurity headers block framing, disallow camera, microphone, location, and payment access, and restrict the origins the app can contact.

What these protections do not mean

No web application can promise perfect security. The optional four-digit privacy screen is a convenience layer on that browser; it is not encryption and does not replace your device passcode. Connected data may be delayed, incomplete, duplicated, or unavailable depending on the institution and Plaid. A read-only connection does not let Siegel Financial move money or place trades.

For users

Use a strong, unique password and sign out on shared devices. Enter institution credentials only in the Plaid Link window opened by the Connected tab, and payment details only on Stripe-hosted checkout. Never put passwords, Social Security numbers, tax IDs, full account numbers, or payment card numbers in plan fields, notes, or support messages.