CipiliCipili

Security

Cipili handles money questions, so the answer to “how is my data protected?” should be specific, not a slogan. Here is exactly how the system is built.

Encryption

Your data is encrypted in transit over TLS and encrypted at rest with AES-256 by our managed database provider. Cipili is served over HTTPS only.

Access control

Every table holding user data is protected by row-level security, enforced by the database itself rather than by application code. A signed-in account can read its own rows and no one else’s, even if a bug in the app asked for more.

Privileged database credentials are used only inside trusted server routes. They are never shipped to the browser.

Bank connections

When bank linking is enabled, Cipili connects through Plaid. You enter your bank credentials with Plaid, never with us, and we never see or store them. Cipili holds only a revocable access token, kept server-side.

Linking is opt-in, consent is recorded when you grant it, and you can disconnect an institution at any time from your settings.

What our AI sees

Cipili uses the Gemini API to turn your numbers into plain-English explanations. Any data sent to it passes through a single internal gateway that strips identifiers first, so the model receives the financial figures it needs to reason about and not your name, email, or account numbers.

The model does not execute transactions, move money, or connect to your accounts. It reads the numbers you have given us and explains options.

Logging

Our logger redacts by default. Account numbers, balances, and transaction details are never written to logs, error reports, or analytics. Access to your data, recommendation generation, and administrative actions are recorded in an audit trail.

Your data, your call

You can delete your profile, financial records, saved recommendations, and any linked bank items from your settings. Deletion is a built-in path, not a support request, and those rows are removed rather than flagged as hidden.

Certifications

Cipili is not yet SOC 2 certified. We would rather say so plainly than display a badge we have not earned. When that changes, it will be stated here with the audit date.

Reporting a problem

Found a vulnerability? Email security@cipili.com. We read every report and will confirm receipt.

Cipili provides financial education, comparisons, and estimates based on the information you provide. It does not provide investment, tax, legal, or accounting advice, and is not a registered investment adviser or fiduciary. Estimates rest on stated assumptions and are not guarantees of future results.