Security
Read-only, and specific about it.
JuniFi asks for read access to every account you own. That deserves detail and an honest list of what is missing — not a padlock icon and the words “bank-level security”.
The short version
JuniFi can read your money and cannot touch it. Your bank credentials never reach our servers; the one token that could read your transactions is encrypted at rest; passwords are hashed and sessions are signed and expiring. JuniFi is also a young product run by one company in Spokane: it has no SOC 2 report, no third-party penetration test, and no second-factor sign-in yet. Those are real gaps and they are listed by name further down this page rather than left for you to discover.
How bank connections work
The part people are right to be nervous about, in the order it actually happens.
- Read-only, by construction.
- Bank and card connections are created through Plaid in read-only mode. JuniFi can read balances, transactions and account metadata. There is no payment, transfer or account-opening capability anywhere in the product — not disabled, not gated behind a permission: not built.
- Your bank credentials never reach us.
- You enter them inside Plaid’s own hosted flow, which JuniFi embeds but cannot read. What comes back to JuniFi is an access token scoped to the accounts you picked. We never see, store, or have any way to recover a bank username or password.
- Those tokens are encrypted at rest.
- The Plaid access token is the one secret in the system that would let someone else read your transactions, so it is never stored in the clear. It is encrypted with Fernet (AES-128-CBC with an HMAC-SHA256 authentication tag) under a key held in the server environment, separate from the database.
- You can revoke it from either end.
- Disconnecting an institution in JuniFi removes the item and its stored token. You can also revoke JuniFi’s access from your bank or through Plaid directly, and the next sync simply fails rather than silently continuing.
- Nothing is sent to your clients.
- The collections workflow composes reminder text for an overdue invoice and stores it. There is no SMTP, mail-API or outbound channel in the product, so a draft cannot leave it — you copy the text, send it from your own inbox, then mark it sent.
How your account is protected
Specific primitives and specific numbers, so you can judge them rather than take a word for it.
- Passwords are hashed, never stored.
- PBKDF2-HMAC-SHA256 with a unique random salt per password and 240,000 iterations, verified in constant time. A database copy does not yield anyone’s password, and nobody at Junious Digital Labs can look yours up.
- Sessions are signed and they expire.
- Signing in sets a cryptographically signed session token in an HttpOnly, SameSite=Lax cookie — marked Secure whenever the connection is HTTPS — with a 30-day lifetime. JavaScript on the page cannot read it, and a tampered or expired token is rejected by the API, not merely by the browser.
- Repeated failed logins are throttled.
- Login attempts are rate-limited per identifier so a stolen email address cannot be used to grind through passwords at full speed.
- Every page and every API call is re-checked.
- Page requests pass a session gate at the edge, and the API independently re-validates the session on every single request. Neither one trusts the other’s word for it.
What is in place, what is next, what JuniFi does not have
The third column is the one that matters. A security page that lists only strengths is a marketing page.
- Read-only bank access via PlaidIn place
In production. No money-movement code exists in the product.
- Plaid access tokens encrypted at restIn place
Fernet, with the key supplied from the server environment.
- Password hashing + signed, expiring sessionsIn place
PBKDF2-SHA256 at 240,000 iterations; HMAC-signed HttpOnly cookie.
- TLS on everything in transitIn place
HTTPS only, with HTTP redirected. No JuniFi traffic moves in the clear.
- Per-user isolation of every financial recordIn progress
Every row already carries the user it belongs to. Making that an enforced boundary rather than a column is the work in flight, and it gates the second account.
- Passkeys and authenticator (TOTP) sign-inIn progress
The data model carries both. Neither flow is built yet, so today the second factor is not available — that is a gap, stated as one.
- Self-service account deletion and exportIn progress
Export exists as CSV and JSON. Deletion is currently done on request by email rather than from a settings screen.
- SOC 2 Type II reportNot yet
JuniFi does not have one and is not in an audit window. Anyone telling you a product this young is SOC 2 audited is telling you something else.
- Third-party penetration testNot yet
None has been commissioned. Worth doing before JuniFi is open to the public, and it has not happened yet.
- Formal bug-bounty programmeNot yet
No programme and no payouts. Reports are still read and acted on — see below.
What happens to the data itself
Security is who can get in. This is what we do with it once we are the ones holding it.
- Your financial data is not sold, brokered or monetised.
- There is no advertising in JuniFi, no affiliate placement of financial products, and no arrangement under which anyone pays for access to your data. The business model is the subscription on the pricing page. That is the whole of it.
- JuniFi does not train anything on your money.
- The CFO runs on Anthropic’s Claude. To answer a question, the figures that question needs are sent to Anthropic and governed by their terms for that service. JuniFi itself builds no model from your data, and does not pool your transactions with anyone else’s for any purpose.
- Only the figures a question needs are sent.
- When you ask the CFO something, it assembles the relevant balances, transactions and remembered facts for that question and sends those. It does not ship your entire financial history on every message.
- The subprocessors are nameable.
- Plaid for bank connectivity, Anthropic for the language model, Contabo for hosting in the United States, and whichever business system you yourself connect. The privacy page is where that list is maintained as it changes.
Found something? Tell us directly.
There is no bounty programme and no triage queue. There is an email address that a human reads.
Email joshj@juniouslabs.digital with the subject line “JuniFi security report”. Include what you found and how to reproduce it. You will get a human reply, and a fix or an explanation of why it is not one.
Please do not test against other people's accounts, run automated scanners against the production host, or access data that is not yours. Report it instead — that is what the address is for.
Where JuniFi runs
- Hosting
- A dedicated virtual server in the United States, behind TLS, operated by Junious Digital Laboratories LLC.
- Data location
- Your financial records are stored in a PostgreSQL database on that server. They are not replicated to a third-party analytics platform.
- Who can reach it
- Administrative access is limited to the company's own operator over a private network. JuniFi has no support staff with a console into your data, because JuniFi has no support staff.
Last reviewed 3 October 2026. This page describes the system as it is built today, not as it is intended to be. When the implementation changes, this page changes with it.