Security at Rupexi

Last updated: 6 June 2026

Protecting your financial data is the foundation of Rupexi. This page describes the technical and organisational measures we use to keep your information safe.

1. Encryption

All data is encrypted in transit using TLS 1.2+ and encrypted at rest using AES-256. Sensitive secrets are managed through a dedicated key-management service.

2. Authentication

Passwords are stored only as salted hashes (never in plain text). The mobile app supports biometric unlock (Face ID, Touch ID, fingerprint), and we support multi-factor authentication.

3. Bank Connections

Where you link a bank or card, we use regulated open-banking aggregators with read-only access. Rupexi can read transaction data to help you — it can never move money.

4. Infrastructure & Access

Our infrastructure runs on hardened cloud environments with network isolation, least-privilege access controls, audit logging, and continuous monitoring. Access to production data is restricted and logged.

5. Compliance

We build our controls to align with recognised frameworks including SOC 2, ISO 27001, and PCI DSS, and we handle personal data in accordance with the EU GDPR and India’s DPDP Act. Current certification status is available on request at security@rupexi.app.

6. Responsible Disclosure

We welcome reports from security researchers. If you believe you’ve found a vulnerability, please email security@rupexi.app with details. We commit to acknowledging reports promptly and will not pursue legal action against good-faith research.

Questions about this document? Contact us at privacy@rupexi.app.