This policy describes how SUPERNIGHT, LLC ("we", "us") protects the systems behind the Copper app and the consumer financial data they process, including data received from Plaid. It applies to everyone with access to Copper's production systems, including employees, contractors, and the company's owner.
1. Ownership and responsibility
Dakota Perry, owner of SUPERNIGHT, LLC, is responsible for information security. That covers keeping this policy current, approving access to production systems, running the reviews below, and leading incident response. Security questions can be sent to the contact address in our Privacy Policy.
2. Data we protect
- Restricted: Plaid access tokens, API secrets and signing keys. Only our servers can read these.
- Confidential: consumer financial data (accounts, balances, transactions) and account details (email, name). Only the person it belongs to, and the people they share a budget with, can access it.
- Internal: source code, configuration and operational logs.
3. Access control
- Least privilege and roles. Access to production systems is granted per role and only as needed. Consumer data is separated in the database by row-level security: people can only read their own data and the budgets they belong to, with owner, editor and viewer roles. Service credentials that bypass those rules exist only in server-side functions and are never shipped to an app.
- Multi-factor authentication for staff. MFA is required on every system that stores, processes or administers consumer data or the code that handles it. That includes the database and hosting providers, Plaid, source control, app-store accounts, and the identity accounts used to sign in to them. Passkeys or hardware-backed methods are used where the service supports them. Credentials are kept in a password manager and are never shared.
- Non-human access. Services authenticate to each other with signed tokens or secret keys sent over TLS. Webhooks from Plaid are checked against their signatures. Secrets live in the hosting providers' secret stores, not in source code.
- Reviews and removal. Access to production systems is reviewed every quarter. When someone leaves or changes role, their access is removed or changed the same day, and any shared secrets they could see are rotated.
4. Consumer authentication
- Consumers sign in with an email and password (stored only as a salted hash by our authentication provider), or with Sign in with Apple or Google. Sessions use short-lived signed tokens.
- Before Plaid Link opens, consumers must pass a second factor. In the iOS app that is Face ID, Touch ID or the device passcode. On the web it is a code from an authenticator app.
- The app can also require a PIN or Face ID to open, and it clears cached financial data when someone signs out.
5. Encryption
- All traffic between apps, browsers and our servers, and between our servers and Plaid, uses TLS 1.2 or later. Older protocols are refused.
- All consumer data is encrypted at rest (AES-256) by our database provider. Plaid access tokens are also encrypted at the application level with AES-256-GCM, using a key kept only in the server secret store, and they are never sent to a device.
- The web app keeps financial data in memory only. The iOS app's offline cache is protected by iOS Data Protection.
6. Secure development
- Changes are reviewed before they are deployed to production. Database changes go through versioned migrations.
- Dependencies are scanned automatically for known vulnerabilities, and the source repository is scanned for committed secrets.
- Production and development use separate credentials. Test data is never copied from production.
7. Vulnerability and patch management
- We fix vulnerabilities in our code and dependencies within these deadlines, counted from when we learn of them: critical within 7 days, high within 30 days, medium within 90 days. Low findings are handled during regular maintenance.
- Every month we check for software that is at or near end of life (runtimes, frameworks, SDKs, operating systems) and schedule upgrades before support ends.
- Work computers use full-disk encryption, a firewall, automatic operating-system and security updates, and a screen lock.
- Our hosting and database providers patch the infrastructure they manage.
8. Logging and monitoring
Authentication, database and server function logs are kept by our providers and reviewed when something looks wrong. Bank-connection errors reported by Plaid are recorded and shown to the affected user so the connection can be repaired.
9. Vendors
We only use vendors that protect data at a level comparable to this policy. Their security reports (for example SOC 2) are reviewed when we start using them and again once a year. Current vendors that handle consumer data are Plaid (bank connections), Supabase (database, authentication and server functions), Railway (hosting), Apple and Google (sign-in and app distribution), RevenueCat (subscription status) and Expo (app builds and push notifications).
10. Incident response
- Detect and triage: confirm what happened and which data and systems are affected.
- Contain: revoke the affected sessions and credentials, rotate keys, and disconnect affected bank connections if needed.
- Recover: fix the cause and restore service.
- Notify: tell affected users, Plaid and any other affected partners without undue delay, and as the law and our contracts require.
- Review: write down the cause and fix, and update this policy if needed.
11. Data retention and deletion
We keep consumer data only while the account is open. People can delete their account in the app at any time. Doing so removes every linked bank at Plaid and permanently deletes their budgets, transactions, images and profile. Removing a single bank disconnects it at Plaid and stops syncing. Backups roll off after a limited period. The full details are in our Privacy Policy. We review our retention practices at least once a year to make sure they still meet applicable privacy laws.
12. Policy review
We review and update this policy at least once a year, and whenever our systems or legal requirements change significantly.