VAULT by PD

Security is a habit, not a headline.

Everything below is implemented today — no unverifiable marketing claims and no bank-grade vocabulary.

Identity & Authentication
Every login uses bcrypt-hashed passwords and optional TOTP-based MFA. Sessions are short-lived, HTTP-only, and rotate on privilege change. Brute-force protection is applied per-email.
Data Protection
Records are stored in per-tenant collections. Documents are stored on isolated storage with signed URLs. VAULT never stores CVV, PIN or OTP.
Workspace Isolation
Every read and write is stamped with a tenant_id. The unmatchable-tenant fallback (2026-07-28) means legacy users with no tenant see zero data until an admin assigns them a workspace.
Household Permissions
Household visibility (Private, Shared Summary, Shared Full, Selected Members) is enforced server-side on every read. Private records never appear in another member's household view.
Documents
Documents can be marked private per-record. Uploaded files are scoped to the current tenant and never returned across workspaces.
Sessions
Active sessions are visible in Settings → Security. Step-up authentication is required for sensitive changes like MFA rotation and password reset.
Privacy Controls
Hide-Values instantly redacts every balance across the app. Household privacy presets let couples and families pick sensible defaults on day one.
Backups
Managed database backups are handled by the platform. VAULT admins can trigger a data export at any time from Settings → Data Export.
Responsible Disclosure
Report vulnerabilities to security@vaultbypd.com. See the disclosure page for scope.
Ready?
Bring your financial life into VAULT.
·@vaultbypd|financevault.pro
© 2026 VAULT by PD · Financial life, organised. VAULT is not a bank, lender, or investment adviser.