Security & Encryption
Last updated: August 29, 2026
Zero-Knowledge Vault
Client-side 256-bit AES encryption ensures only your authorized devices hold the keys to decrypt your finances.
Local-First Storage
Your SQLite database lives directly on your PC, phone, or tablet. Complete speed, privacy, and full offline autonomy.
Zero Bank Credentials
Hyefin never asks for bank usernames, passwords, or bank screen-scraping access. Your credentials never touch our systems.
1. Client-Side Encryption Standards
Hyefin implements modern cryptographic standards to ensure privacy by mathematics, not merely policy:
- 256-bit AES Encryption: All financial database snapshots synchronized to the cloud are encrypted client-side using Advanced Encryption Standard in GCM or CBC mode with HMAC integrity verification.
- PBKDF2 Key Derivation: Master encryption keys are derived on-device using hardened key stretching with high iteration counts and random salts, resisting brute-force and dictionary attacks.
- Zero Server Access: The Hyefin cloud backend never receives your plaintext encryption passphrase. Hyefin servers store and synchronize opaque cipher blobs only.
2. Database Cloud - Any Devices Synchronization
When utilizing Hyefin Plus multi-device synchronization:
- Synchronization always originates from the authorized device holding your database.
- Data in transit is secured with TLS 1.3 encryption on top of the underlying client-side AES-256 payload encryption.
- New devices require authenticated authorization before they are granted access to receive and decrypt your cloud database snapshot.
3. Account Protection & Two-Factor Verification
To prevent unauthorized account takeovers and credential stuffing:
- Multi-Factor Email Verification: Time-sensitive 6-digit one-time passcodes (OTP) are enforced for new registrations, password resets, and critical account actions.
- Session Management: Authenticated sessions use cryptographically signed, short-lived tokens stored in secure, tamper-resistant browser and desktop storage.
- Real-Time Device Broadcast: Administrative actions, password updates, and account status changes are broadcast in real-time to active sessions to trigger immediate security invalidation when warranted.
4. Data Portability & Ownership
You are never locked in. Your data belongs to you:
- Raw SQLite Backups: Export your complete unencrypted or encrypted
.sqlitefile at any time with one click from in-app settings. - Offline Resilience: Even if cloud connectivity is completely disabled or cancelled, the Hyefin desktop and mobile apps continue functioning offline with your local database intact.
- Full Account Purging: You may request complete deletion of your account and cloud sync snapshots at any time.
5. Responsible Disclosure & Security Inquiries
We take the security of our users and their finances seriously. If you have discovered a security vulnerability or have questions regarding Hyefin's encryption architecture, please contact us immediately:
Security Team: contact@hyefin.com
Website: https://app.hyefin.com