Skip to content
Trust, by design

Your household's money deserves real protection.

Firza is built to fintech-grade standards. Here's exactly how we protect your data and keep the record honest.

How we protect you

Four commitments to your money

Privacy, integrity, access, and control — built in, not bolted on.

Privacy on by default

The four-level privacy model starts at totals-only and is enforced on every read — not just hidden in the interface. Personal information is segregated and removed when you delete your account.

A record you can verify

Every change writes a single record in the same transaction, secured by a per-space SHA-256 hash chain with daily anchors — so tampering is detectable, not just discouraged.

Stronger sign-in

Passwordless codes, optional multi-factor authentication with backup codes, step-up checks for sensitive actions, and new-device detection.

Your data, your call

Export your data anytime and delete your account with a 30-day grace period. We honor consent choices and document our data-protection practices.

Coming soon

What's next: encryption at rest

Coming next: field-level encryption at rest. Each user's data will be encrypted with its own key, so a stolen database reveals nothing — and deleting your account cryptographically erases it.

On our roadmap, not yet shipped.

For the technically curious

Under the hood: database role separation, content-security and transport hardening (CSP/HSTS), per-user rate limiting, SSRF guards, optimistic concurrency to prevent lost updates, idempotent writes to prevent duplicates, and a security CI pipeline (dependency auditing, secret scanning, static analysis).

Have a security question?

We're happy to walk your team through our approach and share our data-protection documentation.