Information Security Policy

Owner: Matthew Montney (responsible for information security, privacy, and incident response). Version 2.0. Effective July 22, 2026. Reviewed at least annually and after any material change.

This policy describes how we identify, mitigate, and monitor information security risks for our application, Finance Crystal Ball, a personal budgeting and cash-flow forecasting tool that connects to consumer financial data through Plaid on a read-only basis. It is operationalized through the specific controls below. This document supersedes and consolidates our prior separate Information Security and Multi-Factor Authentication policies.

1. Scope and roles

This policy covers the application, its hosted service, and the infrastructure that accesses or stores consumer financial data obtained via the Plaid API. Matthew Montney is the single administrator and is responsible for information security, privacy, and incident response, and reviews this policy at least annually and after any material change.

2. Data minimization and read-only access

The application is strictly read-only with respect to financial accounts. When a user chooses to connect a bank, we request only the minimum data needed to provide the service: account balances (to show current cash on hand) and transactions (to summarize recent spending). We cannot move money, initiate payments, or make any change to a user's accounts. We never receive or store bank login credentials; those are entered by the user directly with their institution through Plaid Link.

3. Access control (least privilege)

4. Authentication and multi-factor authentication (MFA)

5. Encryption

6. Secure development and secrets management

7. Vulnerability and patch management

8. Monitoring and logging

Web and system access is logged. Authentication failures and administrative actions are observable through server logs, which are reviewed when investigating any suspected issue.

9. Consumer consent and privacy

Consumers grant consent for data access through Plaid Link at the time they connect an account. We do not sell, rent, or share financial data, and do not use it for advertising. Our data-handling and disposal practices are detailed in our Data Retention and Disposal Policy.

10. Incident response

Suspected security incidents are investigated promptly. Affected credentials are rotated and impacted connections revoked. Material incidents affecting consumer data are handled in accordance with applicable law and Plaid's requirements, including timely notification where required.

11. Review

This policy and its controls are reviewed at least annually and updated as practices change. Questions: mattmontneyjr@gmail.com.

Finance Crystal Ball · mattmontneyjr@gmail.com