Compliance
Standards we design around
Finaura's privacy-first architecture makes some compliance obligations moot, and we hold the parts we do control - security and accessibility - to recognized standards.
OWASP ASVS 5.0 (Level 2) - Self-Assessed
Finaura's authentication and data-handling design follows the security controls described in the OWASP Application Security Verification Standard 5.0, Level 2: PBKDF2-SHA-256 password hashing with a random salt, time-based one-time password (TOTP) two-factor authentication, biometric/passkey-backed unlock, and brute-force rate limiting after failed attempts. This is a self-assessment against ASVS controls, not a third-party-certified audit.
WCAG 2.1 AA Accessibility
Every page on this site is tested with the axe-core automated accessibility engine against the WCAG2A, WCAG2AA, WCAG21A, and WCAG21AA rule sets, and currently passes with zero violations. The site includes a skip-to-content link, visible focus states, semantic headings, and alt text on every image.
GDPR - Not Applicable by Architecture
The GDPR governs how personal data is collected, processed, and stored by a data controller. Finaura has no server, no account system, and no analytics, so it never collects, transmits, or stores any personal data anywhere outside your own device. There is no data controller relationship to form because there is no data flowing to Finaura in the first place.
CCPA - Not Applicable by Architecture
The California Consumer Privacy Act regulates the sale and sharing of personal information by businesses. Finaura cannot sell or share your data because it never has access to it - your transactions, budgets, and accounts live only in your browser's local storage on your own device.
No Cookies, No Tracking, No Analytics
This site and the app do not set tracking cookies, run analytics scripts, or use third-party advertising pixels. The only outbound network request on this site is the optional Support contact form, which is submitted directly to Web3Forms.
What this page is, and isn't
This page describes the standards Finaura's design follows and the testing we run ourselves. It is not a third-party certification, an attestation report, or legal advice. If your organization requires formal certification (such as a SOC 2 report or an independently audited ASVS assessment), reach out via the Support page to discuss it.
Want the technical details?
See the Security page for a full breakdown of every protection layer in the app, or the User Guide for setup and configuration steps.
Read the PIN & Security Guide