Trust
SECURITY & DATA PROTECTION
REYES handles your money information. This page documents the controls in place today. It is a description of product behavior, not an independent certification or audit.
Encryption in transit and at rest
Every request to REYES uses TLS 1.2 or higher with modern cipher suites. Application data is stored on a managed Postgres database with AES-256 encryption at rest. Uploaded documents live in private object storage with the same encryption guarantees.
Especially sensitive fields (SSN, full account numbers) carry an additional application-layer protection and are only revealed after a re-prompt for your App Lock passcode or device biometric.
Read-only bank access via Plaid
When you connect a bank, card, or brokerage account, you authenticate inside Plaid's secure flow — never inside REYES. Plaid returns a short-lived access token tied to your REYES account; we never see or store your bank password.
The connection is read-only. REYES cannot move money, change account settings, or initiate transfers from your bank. You can disconnect any institution at any time from Settings → Linked accounts, which revokes the token at Plaid and starts the 30-day data-deletion window described in our Privacy Policy.
Row-level isolation
The database enforces row-level security policies so that each signed-in user can only read and write their own rows. A bug in the application cannot grant cross-account access because the policies are enforced inside the database itself.
Privileged operations are server-side only
Background automation, daily briefings, scheduled scans, dispute escalations, privacy sweeps, and quarterly estimate drafting run from server endpoints that require a service credential. They are not callable from the browser, and the user's subscription plan is read from the server — it cannot be elevated by the client.
The in-app AI assistant requires a valid signed-in session. Bank credentials, full account numbers, and government IDs are never sent to AI providers.
Account access controls
Sign-in is handled by our managed authentication provider. You can protect the app on your device with a 4-digit App Lock passcode and optional Face ID / fingerprint unlock from Settings → Security.
Sensitive actions — revealing an SSN, exporting all data, or deleting your account — can be gated behind a re-prompt for your passcode.
Privacy practices
REYES does not sell personal information, does not share it with advertisers, and does not feed identifiable financial data into third-party advertising systems. Aggregate, anonymous analytics are opt-in and can be disabled at any time from Privacy settings.
The privacy-sweep feature uses the data you provide (name, addresses, phone, email) only to submit opt-out requests to data brokers on your behalf.
Incident response
We monitor for suspicious access patterns, failed-login spikes, and abuse. If we ever experience a security incident affecting your personal information, we will notify affected users and the appropriate regulators in line with applicable law, with the details of what happened, what we did, and what you should do.
Report a vulnerability
Found a security issue? Please email support@e2v.ai with a clear description and reproduction steps. We will acknowledge within two business days and work the issue with you in good faith. Please do not publicly disclose until we have had a reasonable chance to fix.
This page reflects current product behavior and may change as the app evolves. Statements here are not promises of regulatory compliance, certification, or breach-free operation. For data-handling specifics, see the Privacy Policy.
