Skip to main content
EXPOZOR

Security

Built with your privacy in mind.

EXPOZOR is a manual, early-access expense workspace. It stores the records you choose to enter or import, without connecting to a bank or collecting bank credentials.

Security pillars

No bank credentials collected

EXPOZOR uses manual entry and mapped file import. It does not ask for bank credentials or connect to financial institutions.

Expense tracking only

EXPOZOR is not a bank or payment service. It does not access accounts, custody funds, or initiate payments.

HTTPS in transit

The site is configured with HTTPS, HSTS, Content Security Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy headers.

Protected account access

Passwords use scrypt with a unique salt. Session tokens are random, stored as hashes, and delivered in HTTP-only cookies.

No data selling

We do not sell, rent, or share waitlist or workspace data for third-party advertising or marketing.

Self-service data control

Signed-in users can export their complete workspace, review active sessions, and permanently delete the account and its records.

Responsible disclosure

Found a security vulnerability? Please email security@expozor.com with a description of the issue and steps to reproduce.

We review security reports in good faith and may credit researchers with permission.