Report a security concern.
If you believe you found a vulnerability, please send enough detail for the issue to be reproduced and fixed quickly. Reports are reviewed with priority because user trust matters here.
Last updated: July 18, 2026
How to report
Email hello@siegelfinancial.org with the subject Security Report. If you can, include:
- The affected URL, page, or feature.
- Clear steps to reproduce what you found.
- The browser, device, and operating system you used.
- Screenshots or screen recordings if they help explain the issue.
- Your contact information if you want a response.
Safe testing rules
Good-faith reports are welcome. To keep users protected, please stay within these limits:
- Use only your own account and your own test data.
- Do not attempt to view, change, export, or delete another user's data.
- Do not run high-volume automated scans, denial-of-service tests, spam, phishing, or social engineering.
- Do not attempt destructive testing or actions that could interrupt the service.
There is not a paid bug bounty program at this time, so no reward is promised for reports.
Current protections
What these protections do not mean
No web application can promise perfect security. The optional four-digit privacy screen is a convenience layer on that browser; it is not encryption and does not replace your device passcode. Connected data may be delayed, incomplete, duplicated, or unavailable depending on the institution and Plaid. A read-only connection does not let Siegel Financial move money or place trades.
For users
Use a strong, unique password and sign out on shared devices. Enter institution credentials only in the Plaid Link window opened by the Connected tab, and payment details only on Stripe-hosted checkout. Never put passwords, Social Security numbers, tax IDs, full account numbers, or payment card numbers in plan fields, notes, or support messages.