Skip to content
Foliopeak

Security

How your information is handled.

Last updated: 3 October 2026

Foliopeak holds a picture of what somebody owns and owes. That is worth being careful with, and worth being specific about rather than reassuring in general terms. Everything below describes what the software actually does today.

This sits alongside the Privacy Policy, which covers what is collected and on what legal basis, and the Terms.

At a glance

Encrypted connectionYesHTTPS only, TLS 1.2 and 1.3, HSTS. SSL Labs A+, checked 13 Sep 2026.
Encrypted storageYesThe database and the backups are encrypted by their hosting providers.
Encryption of the text you writeYesJournal entries, notes and family map details, with a key kept outside the database. Also your 2FA secret and Google Sheets tokens. Numbers are not.
Two-factor for your accountYesAuthenticator app, with backup codes stored in a form that cannot be read back. Face ID, fingerprint or a security key on top.
See and end your sessionsYesEvery signed-in device listed in Settings; changing your password signs out the rest.
Alerts for a new sign-inYesAn email when your account is signed into from a device it has not used before.
Alerts for account changesYesAn email when your password or sign-in email changes (to the old address), two-factor goes off, or a passkey, API key or AI connection is added.
Staff access to your dataYesOne person, the founder. Nobody else.
Two-factor on the accounts that run FoliopeakYesAll of them - hosting, code, database, payments, email.
Hardware security keys for those accountsYesAdded 20 Sep 2026, alongside the existing two-factor codes.
Automated tests that accounts stay apartYesRun on every change, including household and adviser sharing.
Scanning the software we rely on for security holesYesOn every change; a serious one fails the checks.
Independent penetration testNot yetAn outside expert paid to try to break in. This page will say when one is done, and its scope.
BackupsYesEvery night, in London, in a separate account the site cannot delete from.
Full restore rehearsedNot yetThe process is written and checked against a real backup, not yet run end to end.
Export and deletionYesDownload everything any time; deleting your account removes it.
Notice before a new provider handles your dataYesPrivacy Policy updated and account holders emailed first.
Reporting a data breachYesICO within 72 hours where required; affected people told without undue delay.
Vulnerability reportingYesA named contact, with good-faith protection.

What Foliopeak can and cannot do

It cannot move money. It can't make payments, transfers or trades, and it has no connection to any account that could. It is a record of figures you type in.

It never asks for a bank login. Foliopeak does not use Open Banking and holds no bank logins, so there is nothing of that kind to steal from it. Every number in your account is one you entered, imported from a file, or read off a screenshot yourself.

The family map, part of Household on the Partner plan, is for where things are, not how to get into them. It turns away entries that look like a password, PIN, recovery code or card number.

It is not regulated financial advice. Foliopeak shows your figures and forecasts; it does not recommend, and it is not authorised by the Financial Conduct Authority (FCA).

Where your information is held

Your account and everything in it are stored in a database run by Neon in a UK data centre (AWS London, eu-west-2). The nightly backups are kept by Amazon Web Services in London too, in an account of their own.

Some processing happens outside the UK, and it would be misleading to say otherwise: Cloudflare serves the site from whichever data centre is nearest you, and Stripe, which handles payments, is US-based. Both are covered by recognised legal safeguards for sending data abroad, set out in full under International transfers in the Privacy Policy.

Passwords and signing in

Foliopeak receives your password briefly when you sign in or set one, and passes it to Neon Auth, which handles signing in. We never store it, log it or write it to a database, and what comes back is a session. Neon Auth keeps only a salted one-way hash of it (a scrambled form that can't be turned back into your password), never the password itself, and our application code never reads that hash.

A new password is screened against Have I Been Pwned’s list of breached passwords before it is set. Only the first five characters of a one-way hash are sent to them, never the password.

You can sign in without a password: ask for a link and we email you one that works once and expires after 15 minutes. If you use two-factor, signing in with a link still asks for your code.

Two-factor authentication is available and uses a standard authenticator app. Backup codes are stored one-way hashed, so a copy of the database would not give anyone working codes. Some actions ask for your two-factor code again, or a recent sign-in if you don't use two-factor: exporting all your data, changing your email, and creating an API key that can make changes. (An API key is a code that lets an app or your own tools reach your account.) Deleting your account only asks you to type DELETE, and nothing is deleted for seven days: you are emailed the date, and signing in stops it.

With two-factor on, you can add Face ID, a fingerprint or a security key (a passkey) and use it instead of the code, at sign-in and for those actions. The authenticator app stays as the backup. The face or fingerprint check happens on your device; we keep only the passkey's public key, which can check a signature but cannot make one. Adding a passkey needs your current code or an existing passkey, and we email you when one is added. Turning two-factor off removes them.

Sign-in, sign-up, sign-in links and password reset all have a limit on how often they can be used, per account and per network address. The two limits stop different things: one blocks repeated guessing at a single account, the other blocks one password being tried across many accounts at once.

Asking for a password reset or a sign-in link gives the same response whether or not an account exists for the address, so neither form can be used to find out who has an account here.

Every place you are signed in is listed under Settings, and you can end any one of them, or all the others at once. Changing your password signs out every other session automatically.

If you lose access, a password reset is sent to your email address, and two-factor backup codes - shown to you once, when you turn two-factor on - get you past a lost authenticator. When your account is signed into from a device it has not used before, Foliopeak emails you the time, with a link to your sessions in Settings, which show the browser and a rough location and let you end that session. The device and the location stay out of the email.

You are also emailed when your password is changed or reset, when two-factor is turned off, when a passkey or an API key is added, and when an AI assistant or the iPhone app is given access. A request to change your sign-in email is told to your current address, before the new one has confirmed it, so there is time to stop a change you did not make.

No email Foliopeak sends carries your figures: no balances, amounts, rates or allowances, no names of your accounts, goals, debts, providers or companies, and no location or device. An email says that something has happened or needs a look, and links to the page in Foliopeak where the detail is, behind your sign-in.

Encryption

Everything travels over an encrypted connection (HTTPS, enforced by HSTS), and the stored database is encrypted by the hosting provider.

Only the two newest versions of connection encryption, TLS 1.2 and 1.3, are accepted. The older versions, 1.0 and 1.1, are switched off - they have known weaknesses and no modern browser needs them. An independent SSL Labs scan grades the connection A+ (checked 13 September 2026).

The free text you write is also encrypted before it is stored, with a key kept outside the database: journal entries, the reasons and notes you add to trades, executor notes, notes on share grants, corporate actions (such as share splits) and planned spends, everything you type into a family map entry except its name, and the note you leave for a trusted contact. So are your two-factor secret and the tokens for your Google Sheets connection, if you have one. A leak of the database or of a new backup would not on its own expose any of it.

Your numbers are not encrypted this way, because every total and chart needs them, and neither are names such as account, company and family map entry names. Foliopeak’s own servers hold the key and decrypt what they need - to show you your text or check a two-factor code - so this protects against a leak of the database or a backup, not against the app itself.

Keeping accounts apart

Every time the app reads or saves your data, it looks only at your account, which it knows from your sign-in or from an API key of yours - never from anything the request itself claims. Asking for someone else’s record by its id doesn’t reach it, because the app checks the owner first.

That is checked automatically on every change to the code. One set of tests reads every database query in the code and fails if any touches your data without checking whose it is. Another runs the application's own code against a real database holding several accounts, and tries to reach one account’s holdings, accounts, debts, exports, API data and AI-assistant answers from another. The features that deliberately cross accounts - household sharing, adviser views and a trusted contact's read-only access - are tested hardest: nobody sees a household they haven't joined, a share opens only to the person it was sent to, and a trusted contact sees nothing until it is released, only through their own confirmed account, and nothing once the year is up.

Getting your data out, and deleting it

You can download a copy of everything you have entered at any time, from the Export tab in Settings. It is yours, and you don't need to ask.

Deleting your account removes your login and everything attached to it: accounts, holdings, transactions, goals, journal entries, family map, snapshots, household membership and API keys.

Two things survive, and both are deliberate. Your email address and the reason you gave are kept as a record that the deletion happened and why - a short exit note rather than any of your figures - for 12 months, and then deleted automatically. And your data remains inside existing backups until those backups are deleted, after about three months.

If you want the exit note removed sooner, email hello@foliopeak.com and it will be.

Backups

A full backup is written every night to Amazon Web Services in London, in an account kept apart from the one that runs the site. The site can add a backup but cannot change or delete one, and each is locked for ninety days. AWS encrypts what it stores. Foliopeak also encrypts new backups before they leave, with a key AWS does not hold. The backups exist so that a bad update to the site or a database failure can be put right rather than being final - and because every figure in Foliopeak is one you typed in, there is no bank to re-download it from, so a day is the most that could ever be lost.

Documents you attach to accounts, such as a pension statement, are copied there too: encrypted before they leave, or not copied at all, and copied again every two months, before the older copy is deleted.

Each backup is deleted automatically after about three months, which is why deleted data can stay that long rather than vanishing the same day.

To be plain about testing: the restore process is written down and has been checked against a real backup file, but a full restore into a fresh database has not yet been practised from start to finish.

Who at Foliopeak can reach your data

One person: the founder. Nobody else has access to the live database or the accounts that run the service. If that ever changes, this page will say so.

Every administrative action, and every change to an account's API keys, is written to an audit log that the admin screens can read but not change. It is kept for 24 months.

The accounts that run Foliopeak - hosting, code, database, payments and email - are all protected by two-factor authentication, and each also has a hardware security key as of 20 September 2026.

Keys and secrets

The passwords and keys Foliopeak uses to talk to its providers are stored encrypted in the hosting platform, not in the code: once set, they cannot be read back out, only replaced.

API keys you create are stored only as a one-way hash and shown to you once. Each carries a level of access - read-only by default - can be set to expire, and can be revoked at any time.

Checking our own work

Every change to the code runs all our automatic tests and checks, and a scan of the outside software the site relies on for known security holes; if a serious one is found, the change fails its checks. Updates to that software are suggested automatically when they come out.

Last independently checked on 13 September 2026, for foliopeak.com:

Each badge links to that service's own page, showing its current result rather than this one.

No independent penetration test (paying an outside expert to try to break in) has been carried out yet. When one has, this page will say when, and what it covered.

If something goes wrong

If a security incident affects your personal data, we will report it to the Information Commissioner's Office within 72 hours where the law requires it, and tell the people affected without undue delay - what happened, what information was involved, and what we are doing about it.

Who else handles your data

Neon (database and sign-in), Amazon Web Services (backups, in London), Cloudflare (hosting and delivery), Resend (email), Stripe (payments) and Attio (our customer list - names, emails and plans, never your figures). Google is involved only if you choose to sign in with Google or connect the Sheets export.

Price, currency and property lookups send only what the lookup needs: a ticker symbol, a currency code, or for a property estimate the postcode you enter, sent to HM Land Registry. Never your name, your balances or anything that identifies you.

Each is named, with what they do and where they sit, in the Privacy Policy. Card details never reach Foliopeak; Stripe’s own checkout handles them.

There is no advertising script anywhere on this site. The one analytics script is Cloudflare Web Analytics, which counts page views without cookies or personal data.

Before a new provider starts handling your personal data, we will update the Privacy Policy and email account holders to say who, and why.

Connecting an AI assistant (Cairn)

Cairn lets you point an AI assistant you already use at your own numbers. Cairn is read-only by default. You can choose to create a key with write access, which can only propose changes - new balances, new accounts, bills, journal entries, allowance payments, trades, goals, family map entries or fixes for your notifications. It cannot move money, delete data or change account settings, and nothing changes until you approve it inside Foliopeak.

Every Cairn request, including any update, is recorded for 12 months so you can see exactly what was read or changed and when, and you can clear that record yourself. Foliopeak never sees your conversation with the assistant - only the request it makes.

Worth saying plainly: whatever you ask your assistant, its provider sees, under their terms rather than ours. Connect one you are happy with.

Technical details

Keys made on the Cairn page are read-only, and every route that changes data checks a key's scope, so a read-only key cannot change anything by any route. A key with write access works through Cairn and through Foliopeak's API, and both can only propose a change. It waits in Foliopeak, showing exactly what would change, until you approve or decline it while signed in, and lapses after 7 days. Approval is refused where any relevant underlying value has changed since it was proposed. Revoke a key in Settings and it stops working immediately. Keys are stored only as a hash and are individually rate limited.

The write side, control by control - each one enforced by the code, not asked of the assistant:

  • A write key can only propose. Every write tool - balances, new accounts, bills, journal entries, allowance payments, trades, goals, family map entries, fixes for notifications - creates a proposal. Several at once arrive as one batch. The key applies nothing itself.
  • You approve inside Foliopeak. A proposal is applied only by your tap while signed in, and it is checked again at that moment: approval is refused where any relevant underlying value has changed since it was proposed - a balance or allowance figure that has moved, a holding that no longer exists, a notification already dealt with - and the rest is validated as if you had entered it by hand. A batch is approved or declined whole, and refused whole if any item in it no longer fits.
  • Proposals lapse, and there is a cap. A proposal expires after 7 days, and at most 20 can wait at once. Past that the tools answer with a message to approve or decline some first, so a runaway or hijacked assistant fills one card, not your account.
  • Write access is a deliberate choice. Only a key you create in Settings, choosing write access, can propose. Connecting an assistant with one click issues a read-only key, and no assistant can raise its own permission.
  • Rate limited. A key may propose at most 30 changes an hour.
  • On the record. Every request a key makes is in the Cairn request log, and every approval and decline is in your account's audit log.
  • Revoked in one click. Revoking a key in Settings stops it immediately.

Reporting a vulnerability

If you have found a problem, please tell us before telling anyone else and give us a reasonable chance to fix it. Email hello@foliopeak.com.

We will not pursue or support legal action against anyone acting in good faith: testing only against your own account, not accessing or altering anyone else’s data, no denial of service, and no social engineering of our staff or providers. We will tell you what we did about your report.

This page describes the position on the date above. Security is not a state you arrive at, and where something is known to need work it is being worked on rather than described here as finished.

The rest of Foliopeak is invite-only for now. Join the early-access list and we will tell you when it opens.

Foliopeak is a UK wealth tracker, not financial advice · hello@foliopeak.com
Rackel Ltd is registered in England and Wales, company number 14567038. Registered office: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
Learning Hub · This tax year · Privacy policy · Terms · Security