Security is the foundation. Privacy is the promise.
Kaban is engineered from the ground up as a private personal sanctuary for your financial life. Explore our technical boundaries, cryptographic flow, and zero-telemetry audit.
Data Protection Pipeline
Four Layers of Defense
How your balances, transactions, and goals travel safely between your browser and local database.
Your financial transactions & vaults live locally on your device first in sandboxed browser storage.
All sync payloads to Supabase are encrypted end-to-end with forward secrecy and strict HSTS headers.
Database tables enforce Row-Level Security via verified sessions. Client actor IDs are never trusted.
Zero Google Analytics, Facebook Pixels, or Mixpanel scripts. Your financial habits are never for sale.
Local-First IndexedDB Isolation
Unlike traditional cloud-only banking apps, Kaban stores your active workspace locally on your device in sandboxed IndexedDB. Queries execute in sub-milliseconds without network latency, and changes queue safely in a persistent client-side outbox.
Cryptographic Session Verification
Every authenticated server request derives user identity strictly from verified server-side Supabase sessions (`auth.uid()`). Client-supplied actor IDs are discarded to prevent spoofing, and PostgreSQL Row-Level Security (RLS) is enforced at the database kernel level.
Review-First Tala AI Boundaries
Tala is built under an immutable Review-First Constitution. Tala can read and draft suggestions, explain calculations, and categorize receipts, but can never execute financial transactions, move funds, or commit ledger writes without your explicit click.
Audited Zero-Tracker Architecture
Inspect our source code and network inspector: you will find zero Google Analytics, zero Meta tracking pixels, zero Mixpanel telemetry, and zero behavioral advertising SDKs. Your spending choices are yours alone.
Vulnerability Disclosure
Responsible Disclosure & Support
We take security concerns seriously and work with independent security researchers.
If you believe you have discovered a potential security vulnerability in Kaban, please submit a report via our confidential feedback form with “Security Concern” selected. We commit to acknowledging reports within 24 hours.
Contact Security Team