Hyefin
  • Features
  • Download
  • Pricing
  • Terms
  • Privacy
  • Security
  • Open Web App
Log in Get Started Free
Terms of Service Privacy Policy Security Architecture

Security & Encryption

Last updated: August 29, 2026

Zero-Knowledge Vault

Client-side 256-bit AES encryption ensures only your authorized devices hold the keys to decrypt your finances.

Local-First Storage

Your SQLite database lives directly on your PC, phone, or tablet. Complete speed, privacy, and full offline autonomy.

Zero Bank Credentials

Hyefin never asks for bank usernames, passwords, or bank screen-scraping access. Your credentials never touch our systems.

1. Client-Side Encryption Standards

Hyefin implements modern cryptographic standards to ensure privacy by mathematics, not merely policy:

  • 256-bit AES Encryption: All financial database snapshots synchronized to the cloud are encrypted client-side using Advanced Encryption Standard in GCM or CBC mode with HMAC integrity verification.
  • PBKDF2 Key Derivation: Master encryption keys are derived on-device using hardened key stretching with high iteration counts and random salts, resisting brute-force and dictionary attacks.
  • Zero Server Access: The Hyefin cloud backend never receives your plaintext encryption passphrase. Hyefin servers store and synchronize opaque cipher blobs only.

2. Database Cloud - Any Devices Synchronization

When utilizing Hyefin Plus multi-device synchronization:

  • Synchronization always originates from the authorized device holding your database.
  • Data in transit is secured with TLS 1.3 encryption on top of the underlying client-side AES-256 payload encryption.
  • New devices require authenticated authorization before they are granted access to receive and decrypt your cloud database snapshot.

3. Account Protection & Two-Factor Verification

To prevent unauthorized account takeovers and credential stuffing:

  • Multi-Factor Email Verification: Time-sensitive 6-digit one-time passcodes (OTP) are enforced for new registrations, password resets, and critical account actions.
  • Session Management: Authenticated sessions use cryptographically signed, short-lived tokens stored in secure, tamper-resistant browser and desktop storage.
  • Real-Time Device Broadcast: Administrative actions, password updates, and account status changes are broadcast in real-time to active sessions to trigger immediate security invalidation when warranted.

4. Data Portability & Ownership

You are never locked in. Your data belongs to you:

  • Raw SQLite Backups: Export your complete unencrypted or encrypted .sqlite file at any time with one click from in-app settings.
  • Offline Resilience: Even if cloud connectivity is completely disabled or cancelled, the Hyefin desktop and mobile apps continue functioning offline with your local database intact.
  • Full Account Purging: You may request complete deletion of your account and cloud sync snapshots at any time.

5. Responsible Disclosure & Security Inquiries

We take the security of our users and their finances seriously. If you have discovered a security vulnerability or have questions regarding Hyefin's encryption architecture, please contact us immediately:

Security Team: contact@hyefin.com

Website: https://app.hyefin.com

Hyefin

Night-vision for your personal finances.

Product

Features Downloads Pricing Web app

Features

Receipt Scanner Money Coach Price Tracker Statement Parser

Legal

Privacy Terms Security
© 2026 Hyefin. All rights reserved. Made for the night. 🌙