Protected web surface
MoneyKai deploys security headers that limit framing, MIME sniffing, referrer leakage, and unnecessary browser capabilities.
Controlled sign-in flow
Authentication requests go through a gateway flow with bounded request timeouts and clear failure handling.
User-controlled backups
Backup and restore flows are explicit user actions, with encrypted backup files available where supported.
What MoneyKai protects
These are the practical controls worth surfacing publicly. The page intentionally avoids listing every internal setting.
Transport and browser protections
The website is configured with defensive browser policies so the public surface is harder to embed, spoof, or misuse from another origin.
HTTPS hardening with HSTS on production responses.
Content Security Policy boundaries for scripts, frames, images, and network connections.
Clickjacking and content-type protections with frame and MIME sniffing controls.
Account access safeguards
MoneyKai keeps account access flows narrow and predictable, with explicit authentication requests and user-facing error handling.
Email and Google sign-in are routed through the web authentication gateway.
Client-side attempt throttling helps reduce repeated sign-in and password reset abuse.
Authentication responses are validated before a session is accepted by the app.
Data and backup boundaries
MoneyKai avoids vague security claims. The product explains where financial records live and which actions the user controls.
Finance records are handled inside authenticated app flows.
Backup files are created or restored only when the user starts that action.
Encrypted backup files are positioned as user-controlled continuity, not a hidden cloud sync promise.
Operational care
Security is also about reducing accidental exposure and keeping sensitive workflows conservative by default.
API helpers apply response security headers and request body limits.
Sensitive capabilities such as camera, microphone, geolocation, payment, USB, and Bluetooth are restricted by policy on the public site.
Security and privacy questions can be sent to the published support channel.
Responsible security expectations
Security communication should help users understand risk without turning into a checklist of internal controls.
MoneyKai is a personal finance workspace, not a bank or regulated financial custodian.
No software can promise absolute security, so the product avoids blanket guarantees.
Do not send passwords, full card numbers, or sensitive document contents by email.
For security, privacy, or data-related questions, contact support@moneykai.app.