Server-side token handling
Long-lived provider access tokens are handled server-side, stored in encrypted form, and are not placed in browser storage.
Security overview
No system can promise perfect security. SIX reduces exposure through local-first processing, controlled data promotion, and separation between public and private surfaces.
Reviewed July 16, 2026
Long-lived provider access tokens are handled server-side, stored in encrypted form, and are not placed in browser storage.
Core finance processing and canonical records remain in the owner-controlled operational environment.
Provider records enter a review stage. Explicit approval is required before they become trusted canonical data.
Public information is separated from private operations. Production safeguards limit unsafe or unintended operational changes.
Logs are designed to avoid sensitive values, and public API responses are restricted to information appropriate for their purpose.
SIX does not automatically trade, transfer funds, or execute payments. Analysis does not grant transaction authority.
Responsible reporting
Email ricardo.suarez@outlook.com with a concise description and safe reproduction details. Do not include passwords, access tokens, complete account numbers, or other sensitive financial data. Please avoid accessing, changing, or retaining data that is not your own.