Security & Vulnerability Disclosure

Last updated 31 July 2026

Caspian handles financial data, so security is foundational to everything we build. This page describes how we protect your data and how to report a security issue to us.

1. How We Protect Your Data

  • Encryption in transit— all connections use TLS. There is no unencrypted access to any Caspian service.
  • Encryption at rest— databases and backups are encrypted at rest. Third-party access credentials (such as Google OAuth tokens) are additionally encrypted at the application layer.
  • Read-only bank access— open banking connections are read-only. Caspian can never move your money.
  • Least-privilege access— production data access is restricted, logged, and limited to what operating the service requires.
  • No data sales, no ads— we do not sell personal data and do not use it for advertising.

2. Reporting a Vulnerability

If you believe you have found a security vulnerability in Caspian, we want to hear about it. Email [email protected] with:

  • A description of the issue and where you found it
  • Steps to reproduce it
  • Any relevant screenshots, logs, or proof-of-concept detail

We will acknowledge your report within 3 business days, keep you informed of progress, and let you know when the issue is resolved. We ask that you give us a reasonable opportunity to fix an issue before disclosing it publicly.

3. Safe Harbour

We will not pursue legal action against researchers who act in good faith: access only the minimum data necessary to demonstrate an issue, do not access, modify, or delete other users' data, do not degrade the service, and report findings to us promptly and confidentially. Testing that involves social engineering, denial of service, or physical access is out of scope.

4. Scope

In scope: Caspian mobile apps, app.caspian.global, api.caspian.global, and this website. Out of scope: third-party services we integrate with (report issues in those to the relevant provider) and findings requiring physical access to a user's device.

5. Machine-Readable Policy

This policy is also published at /.well-known/security.txt.