Security Architecture

Protecting your financial signal with institutional-grade cryptography and zero-trust engineering.

Data Encryption Standards

At Maxint, we employ defense-in-depth cryptographic measures across all operational layers:

  • Encryption in Transit: All data transmitted between client devices, mobile applications, and our servers is secured using modern TLS 1.3 protocols with strict cipher suites.
  • Encryption at Rest: All databases, document storage volumes, and backups are encrypted using AES-256 encryption.
  • Encrypted Statement Ingestion: Financial statements and receipts uploaded for optical character recognition (OCR) and server-side decryption are parsed within isolated, ephemeral memory environments and encrypted immediately upon persistence.

Hardware-Backed Passkeys and Authentication

We have eliminated the vulnerabilities of traditional passwords and SMS two-factor codes by supporting native Passkeys (FIDO2 / WebAuthn standard):

  • Phishing Resistance: Passkeys use public-key cryptography tied cryptographically to our verified domain records. Credentials cannot be intercepted, replayed, or phished.
  • Biometric Enclave Isolation: Biometric verification (such as Apple Touch ID, Face ID, or Windows Hello) occurs strictly within your local device's Secure Enclave or Trusted Platform Module (TPM). Your biometric markers are never transmitted to our servers.
  • Multi-Device Credential Management: Users can audit and revoke individual device credentials at any time directly from account security settings.

Artificial Intelligence and Finsight Security

Our AI assistant, Finsight, is built on a zero-data-retention foundation designed specifically for financial workflows:

  • Zero Model Training Guarantee: Customer ledger entries, transactions, invoice images, and conversation transcripts are never used to train public machine learning or foundational AI models.
  • Tenant Isolation: AI query contexts are isolated per user session. Queries to enterprise LLM providers (such as Google Cloud Gemini and Anthropic) operate under private, non-logging enterprise endpoints.
  • Model Context Protocol (MCP) Security: Integrations with external AI orchestrators require explicit OAuth consent flows, scoped granular permission tokens, and support immediate token revocation.

Financial Data and Banking Rails

Maxint connects to financial institutions through accredited, SOC 2 compliant aggregation partners (including Plaid and GoCardless):

  • Zero Credential Storage: Maxint never views, handles, or stores your banking passwords.
  • Read-Only Bank Feeds: Financial aggregation connections operate on a strictly read-only basis. Maxint cannot initiate unauthorized fund transfers.
  • PCI-DSS Compliance: Customer payment processing for subscriptions and invoicing complies with rigorous PCI-DSS Level 1 standards.

SOC 2 Type II Compliance

Maxint maintains SOC 2 Type II compliance, verifying that our security controls, system availability, data confidentiality, and operational processes are audited regularly by independent third-party certification bodies.

Infrastructure and Operational Resilience

  • Continuous Threat Monitoring: 24/7 automated anomaly detection, vulnerability scanning, and intrusion prevention systems.
  • DDoS Protection: Global edge routing and automated DDoS mitigation provided through enterprise CDN networks.
  • Redundancy & Backups: Multi-region data replication with regular disaster recovery testing.
  • Least-Privilege Access: Internal administrative access requires hardware security keys, role-based access controls (RBAC), and immutable audit logging.

Mobile and Widget Sandboxing

On mobile platforms, live home screen widgets utilize sandboxed, encrypted on-device shared containers to display balance overviews without exposing full ledger records to unauthenticated device memory.

Responsible Vulnerability Disclosure

We welcome collaboration with the security research community. If you discover a potential vulnerability within our platform, please report it immediately to our security response team atsecurity@maxint.com. We commit to prompt acknowledgment and coordinated remediation.

Contact Security

For security inquiries, audit verifications, or compliance reports, contact our security team atsecurity@maxint.com.