Security
Security is part of the product.
Spliq is designed to handle personal budgeting and shared expense information with a security-first approach. We describe our controls plainly rather than using unsupported claims such as “bank-grade” security.
Data protection
- HTTPS/TLS is used for data transmitted between supported clients and Spliq services.
- Production data is hosted using established cloud infrastructure with access controls appropriate to the service.
- Secrets and service credentials are kept outside the public source code and should be supplied through deployment environment configuration.
- Administrative access is restricted to authorized operators.
Account and application security
- Authentication and authorization controls are used to protect account-level functionality.
- Administrative routes are separated from public content and excluded from search crawling.
- API endpoints validate requests and should expose only the data needed for the requested operation.
- Security and diagnostic logging may be used to investigate failures and suspicious activity.
AI data handling
AI-assisted features process the context needed to answer a user's request. Users should avoid entering credentials, payment-card security codes, or other information that is unnecessary for the task.
AI responses are generated assistance, not guaranteed financial advice.
Responsible security communication
Spliq will update this page as infrastructure and controls mature. We do not claim a certification, audit, penetration test, encryption standard, or compliance status unless it has actually been completed and can be substantiated.
Report a security concern
If you believe you have found a security issue, contact info@spliqcloud.com and include enough detail for us to reproduce the problem. Do not include passwords, access tokens, or private financial information in the initial report.
