Security
Last updated: October 4, 2026
Simura is operated by Cubit Vault LLC ("we," "us," or "our"). You trust us with information about your money, and we take that seriously. This page explains, in plain terms, how we protect your data, how bank connections work, and how to tell us about a security problem.
How we protect your data
- Encrypted in transit. All traffic between you and Simura — the website, the web app, and our mobile apps — is encrypted over HTTPS.
- Bank access tokens stay on our servers. The tokens that let us fetch data from your linked accounts are held in an encrypted secrets vault on our servers. They are never sent to the app or to your device.
- Your data is walled off from other accounts. Every database table that holds your information uses row-level access control, so an account can only read its own data.
- Secure storage on your phone. On iPhone and Android, your sign-in session is stored in the device's secure keychain or keystore.
- Automatic app lock. The app locks itself after 5 minutes of inactivity. You unlock it with your password or, if you turn it on, with biometrics such as Face ID or a fingerprint.
- No personal information in our logs. We keep your financial details, your email address, and other personal information out of our application logs.
Bank connections
We use Plaid to connect your bank and financial accounts to Simura.
- We never see or store your bank username or password. You sign in to your bank through Plaid, not through us.
- We receive read-only data: balances and transactions, and, if you choose to share them, investments and liabilities. Simura cannot move money or make changes to your accounts.
- When you remove a bank connection or delete your Simura account, we revoke that connection with Plaid.
Access within our company
Access to our production systems is limited to the people who need it to run the service. Access is granted on a least-privilege basis and reviewed on a set schedule under our access control policy. We maintain written policies for information security, access control, data retention, vulnerability management, and incident response.
Data retention and deletion
We keep your information for as long as your account is active or as needed to provide the service, and you can delete your account at any time. For what we keep, for how long, and what happens when you delete your account, see the "Data retention" section of our Privacy Policy and our account deletion page.
Reporting a security issue
If you believe you've found a security vulnerability in Simura, please email [email protected] with "Security" in the subject line. Include enough detail for us to understand and reproduce the issue.
We'll acknowledge your report and keep you updated as we work on it. When looking into an issue, please:
- Give us reasonable time to fix the problem before disclosing it publicly.
- Don't access, modify, or delete other users' data. Use only accounts you own.
- Don't degrade the service for others, and don't run automated scanning or denial-of-service attacks.
Our security contact is also published in machine-readable form at /.well-known/security.txt.