Security isn't a feature.
It's the foundation.

We built the security architecture before writing a single line of product code. When you trust an AI with your finances, email, calendar, and health data, that trust has to be earned at every layer.

Passkey-only authentication

NIST SP 800-63-4 aligned

Abundera does not use passwords. Authentication is exclusively through WebAuthn/FIDO2 passkeys—the same cryptographic standard used by Apple, Google, and Microsoft for their highest-security accounts.

Passkeys are phishing-resistant by design. There is no password to steal, no OTP to intercept, no secret question to guess. Your private key never leaves your device. The server only stores a public key that is useless without your biometric or device PIN.

Phishing-proof
Cryptographically bound to the domain. Fake sites cannot request your credential.
No shared secrets
Nothing stored on our servers can be used to impersonate you.
AAL2 / AAL3
Synced passkeys meet AAL2. Device-bound passkeys meet AAL3.
Recovery (planned)
TOTP recovery codes with additional MFA gating for account recovery.

Private AI infrastructure

Every AI model that processes your data runs on private, dedicated infrastructure. Abundera does not call OpenAI, Google, Anthropic, or any third-party AI API with your information. Your financial records, emails, calendar, and health data never touch a shared compute environment.

This is not a wrapper around someone else's model. We run fine-tuned models on hardware we control—not multi-tenant cloud GPUs where your data could be logged, cached, or used to improve models for other customers.

Dedicated hardware
Private GPU infrastructure. No shared compute with other tenants.
No external APIs
Your data never leaves our infrastructure for AI processing.
Fine-tuned models
Purpose-built for financial, benefits, and health reasoning.
Isolated inference
Each user's data processed in isolation. No cross-contamination.

Zero-knowledge data architecture

Abundera is built on a zero-knowledge design. Your data is encrypted at rest and in transit with TLS 1.3. Financial connections through Plaid are strictly read-only—Abundera cannot move money, make purchases, or modify your accounts.

There is no centralized database of user financial data. Processing happens at the edge on Cloudflare's global network, which means your information is handled close to where you are, not in a single data center halfway around the world. Even our own engineers cannot read your financial records or health data.

Encrypted everywhere
TLS 1.3 in transit. Encrypted at rest. No plaintext storage.
Read-only finances
Plaid connections cannot move money or modify accounts.
Edge-processed
Data processed on Cloudflare's edge, close to you.
No central database
No single repository of all user financial data.

You control every permission

Abundera operates on a progressive trust ladder. You start at Level 1 (Observer), where the system can only watch and report. You decide if and when to grant more autonomy. Every permission is individually revocable at any time.

If anything goes wrong—or you simply change your mind—text STOP to halt all automation instantly. Full data export and permanent deletion are available on request, no questions asked.

1
Observer
2
Advisor
3
Co-Pilot
4
Autopilot

What we don't do

Some commitments are best stated as absolutes.

  • Never sell your data. Not to advertisers. Not to data brokers. Not to anyone.
  • Never train models on your data for other users. Your information improves your experience only.
  • Never share data with third parties for advertising. No ad networks. No tracking pixels. No behavioral profiling.
  • Never store passwords. We don't have them. Passkey-only means there is no password database to breach.
  • Never access accounts without explicit permission. Every integration requires your direct authorization.
  • Never send your data to public AI services. No OpenAI, no Google, no Anthropic API calls with your information.

Infrastructure

The platform is built on battle-tested infrastructure with security enforced at every layer.

  • HTTPS everywhere with HSTS preloading
  • Cloudflare Pages + Workers for edge-first processing
  • D1 encrypted database on Cloudflare's global edge
  • Security headers — CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy
  • Rate limiting on all API endpoints
  • SOC 2 Type II certification planned for launch

Responsible disclosure

If you discover a security vulnerability, we want to hear about it. We take every report seriously and will work with you to understand and resolve the issue promptly.

Please do not publicly disclose any vulnerability before we have had a chance to address it. We commit to acknowledging receipt within 48 hours and providing a timeline for a fix.

[email protected]
← Back to home