EXPOZOR's Security Philosophy: Privacy by Architecture
Financial data is sensitive. Here is the conservative security posture EXPOZOR can state today while the product is waitlist-only.
Start with what is real
EXPOZOR is currently a waitlist-stage public site. The concrete data flow today is waitlist signup data: email, source, referrer when provided by the browser, default locale, and signup timestamp.
The site does not currently store transaction data, uploaded receipts, screenshots, CSV files, payment details, or bank credentials.
HTTPS and browser protections
The web app is configured with HTTPS, HSTS, Content Security Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy headers.
These controls do not replace a full production security program, but they are real controls in the current app configuration.
No bank credentials
EXPOZOR does not ask for, collect, or store your bank credentials, passwords, or PINs. Manual expense entry is the first workflow; upload and import workflows are planned for early access.
Expense tracking only
EXPOZOR is not a bank or payment service. It does not access accounts, custody funds, or initiate payments. Shared household expense tracking is planned as manual notes only.
Analytics and tracking
No analytics provider is currently active in the codebase. If analytics are added later, they should be disclosed on the Subprocessors and Cookie Policy pages before launch.
Your data, your choice
While the product is waitlist-only, you can contact support to request deletion of your waitlist record. More complete data controls should be documented before account-based product features launch.
Responsible disclosure
If you find a security vulnerability, email security@expozor.com with a description of the issue and steps to reproduce.
What EXPOZOR is working toward
As EXPOZOR moves beyond the waitlist stage, the security page and legal pages should be updated with confirmed production details, subprocessors, and user controls.