Last updated: 4 August 2026
Our security approach
ixpend is being built around data minimisation, least-privilege access and secure defaults. We collect only what is needed to provide the service and treat financial information as highly sensitive.
Financial calculations
Authoritative calculations will run through tested, deterministic systems. Important recommendations will record the data used, assumptions, calculation version, confidence and result so that decisions can be explained and reviewed.
Bank connections
When account connections become available, authentication will be handled by regulated or appropriately authorised providers. ixpend will not ask for or store your online banking username or password.
Access and protection
Production systems will use encryption in transit and at rest, controlled access, monitoring, secure development practices and regular security testing. Access to sensitive information will be limited to authorised purposes.
Your control
You will be able to review connected services, disconnect providers, correct information and request deletion, subject to legal and operational requirements.
Responsible disclosure
If you believe you have found a security issue, please do not share it publicly. Send the details to security@ixpend.com so we can investigate responsibly.
Early-stage notice
ixpend is still in development. This page describes our security direction and intended launch standards; it is not a certification or a claim that every planned control is already operational.