Security by design
CASE Budget is designed around authenticated access, protected workspaces, role-based permissions, restricted server operations, and database-level security. Security controls will continue to evolve as the platform, integrations, and subscription features grow.
Security overview
CASE Budget is designed to protect sensitive personal and financial information through multiple layers of security. These layers include secure authentication, database access controls, workspace permissions, protected server operations, monitoring, and documented support procedures.
Security controls are intended to reduce the risk of unauthorized access, data loss, misuse, alteration, and disclosure. No platform can guarantee absolute security, but CASE Budget is designed to apply reasonable safeguards based on the sensitivity of the data and the type of access being performed.
Secure authentication
Account sessions are managed through supported authentication services with protected cookies and server-side session handling.
Multi-factor authentication
CASE Budget is designed to support optional MFA for customers and stronger requirements for privileged administrative roles.
Row Level Security
Database policies restrict users to records they are authorized to access within their account and workspace.
Role-based permissions
Personal, household, business, organization, support, platform-admin, and master-admin roles are separated by authorization rules.
Server-only credentials
Administrative service-role credentials are kept in server-only environment variables and are not exposed to browser clients.
Operational monitoring
Security events, errors, and application activity may be logged and reviewed to detect suspicious behavior and reliability issues.
Account security
CASE Budget accounts are protected through controls designed to verify identity, preserve session integrity, and reduce unauthorized access.
- Passwords are handled through the configured authentication provider rather than stored directly in CASE Budget application tables.
- Password-reset links are time-limited and require a valid recovery session.
- Email-confirmation flows help verify ownership of an email address.
- Authentication sessions may be revoked when a user signs out, changes credentials, or when suspicious activity is detected.
- Inactive, suspended, or disabled profiles may be prevented from accessing protected areas.
- Administrative and support accounts may be subject to additional security requirements.
Use a unique password
Your CASE Budget password should not be reused for email, banking, social media, or other services.
Authentication and session protection
CASE Budget uses supported authentication services and server-side session handling to control access to protected application routes.
- Secure cookies may be used to maintain authenticated sessions.
- Session tokens are refreshed through protected server-side flows.
- Protected routes verify the current authenticated user before returning private content.
- Authentication callbacks validate redirect paths to reduce open-redirect risk.
- Expired, malformed, missing, or invalid sessions are rejected.
- Password recovery, account confirmation, and invitation links are validated before a session is established.
Multi-factor authentication
CASE Budget is designed to support optional multi-factor authentication using compatible authenticator applications. MFA may be required for certain privileged roles, sensitive administrative operations, or high-risk account actions.
- MFA enrollment should require verification before the factor becomes active.
- Recovery or factor-removal workflows should require additional identity checks.
- Master-admin and platform-admin actions may require a higher assurance level.
- Users should store recovery information securely and never share verification codes.
Access controls and permissions
CASE Budget separates account, workspace, support, and platform permissions so that users can access only the information and actions appropriate to their role.
Workspace roles
- Owners may manage workspace settings, members, and eligible destructive actions.
- Administrators may manage many workspace functions without receiving unrestricted platform access.
- Members may create or edit eligible financial records according to workspace permissions.
- Viewers may receive read-only access to eligible workspace information.
- Suspended or removed members should not retain active workspace access.
Platform roles
- Regular users access only their own authorized workspaces and records.
- Support administrators may receive limited tools for customer support and issue investigation.
- Platform administrators may manage broader application operations subject to authorization controls.
- Master administrators may perform XilAire Technologies platform-management functions that are unavailable to customer accounts.
- Privileged roles should be assigned only through trusted server-side or database-controlled operations.
Least-privilege access
Access should be limited to the minimum information and functionality needed to perform an authorized task.
Data protection
CASE Budget uses safeguards intended to protect data while it is transmitted, stored, accessed, and processed.
- Network communications should use encrypted HTTPS connections.
- Authentication credentials and service-role keys must remain in protected server environments.
- Sensitive application data is stored in access-controlled databases.
- Row Level Security policies restrict access to authorized rows.
- Workspace identifiers are used to separate customer and household data.
- Database functions performing privileged operations are restricted to trusted roles.
- Backups and recovery processes may be used to support continuity and restoration.
- Sensitive values should be excluded from analytics, client logs, and public error messages.
Financial information
Financial information may include transaction amounts, account balances, budget assignments, debt balances, bill details, savings goals, and investment information. Such information should be exposed only to authorized users and services needed to provide the requested feature.
Application security
CASE Budget is designed with application-level safeguards that reduce common web and authorization risks.
- Server Components and server actions are used for protected operations when appropriate.
- Administrative clients are marked server-only and must not be imported by browser components.
- Redirect destinations are validated before navigation.
- User-supplied input is validated before authentication or database operations.
- Error messages are normalized to avoid exposing unnecessary internal details.
- Account-recovery flows avoid confirming whether an email address is registered.
- Database functions use explicit search paths and restricted execution privileges.
- Direct browser access to privileged provisioning and role-management functions is revoked.
Security is part of development
New CASE Budget features should be reviewed for authentication, authorization, data exposure, input validation, logging, and subscription-access risks before release.
Infrastructure and service providers
CASE Budget may rely on cloud, authentication, database, email, payment, monitoring, and financial-data providers to operate the platform.
- Providers should be selected based on reliability, security capabilities, and business requirements.
- Administrative access to provider dashboards should be restricted to authorized personnel.
- Production credentials should be separated from development and testing credentials.
- Service-role and secret keys should never use public environment-variable prefixes.
- Provider access should be reviewed when personnel, systems, or responsibilities change.
- Third-party incidents may require coordinated investigation, containment, and user communication.
Third-party providers maintain their own security programs and may process information according to their agreements with XilAire Technologies and their published policies.
Monitoring, logging, and audit records
CASE Budget may record security, access, operational, and error information to support monitoring, troubleshooting, abuse prevention, and investigations.
- Authentication success and failure events.
- Password recovery and account-confirmation activity.
- Privileged role assignments and removals.
- Workspace membership changes.
- Administrative customer-support access.
- Subscription and billing state changes.
- Application errors, failed database operations, and service outages.
- Suspicious request patterns, rate-limit events, and potential abuse.
Logs should avoid unnecessary sensitive financial values, passwords, MFA codes, full payment details, or secret keys. Retention periods may vary based on security, operational, legal, and regulatory needs.
Customer support and administrative access
Authorized XilAire Technologies personnel may require limited access to customer account or workspace information to resolve support, security, subscription, or platform issues.
- Support access should be limited to authorized personnel with an operational need.
- Administrative actions should be associated with the staff member performing them.
- Support personnel should access only the minimum information required to investigate the issue.
- Highly sensitive actions may require platform-admin or master-admin authority.
- Customer data should not be copied into unsecured communication channels.
- Support access may be logged for accountability and incident review.
XilAire master administration
Master-admin access is intended for authorized XilAire Technologies platform management, customer support escalation, security response, and operational recovery.
Security incident response
XilAire Technologies may investigate suspected security incidents involving CASE Budget, customer accounts, service providers, or infrastructure.
- Identify and validate the suspected incident.
- Contain affected accounts, sessions, credentials, services, or systems.
- Preserve relevant logs and evidence.
- Remove unauthorized access and remediate the cause.
- Restore affected services and verify security controls.
- Assess whether personal or financial information was involved.
- Notify affected users, providers, regulators, or authorities when required.
- Document lessons learned and improve safeguards.
CASE Budget may temporarily suspend accounts, revoke sessions, disable integrations, restrict features, or require credential resets when necessary to protect users and the platform.
Your security responsibilities
Users also play an important role in protecting CASE Budget accounts and financial information.
- Use a strong and unique password.
- Protect access to your email account and mobile device.
- Enable multi-factor authentication when available.
- Do not share passwords, recovery links, MFA codes, or session information.
- Review workspace members and permissions regularly.
- Remove former household, business, or organization members promptly.
- Keep devices, browsers, and operating systems updated.
- Avoid accessing CASE Budget from untrusted or shared devices.
- Sign out after using public or shared computers.
- Report suspected unauthorized activity promptly.
Protect your email account
Anyone who gains access to your email may be able to request password-recovery links or receive account-security messages.
Report a security concern
Report suspected vulnerabilities, unauthorized access, account compromise, or security concerns to XilAire Technologies.
Include
- A clear description of the issue.
- The affected page, feature, or account area.
- The approximate date and time observed.
- Steps to reproduce the issue when applicable.
- Screenshots with sensitive information removed.
- A safe method for contacting you.
Do not include
- Your password.
- Multi-factor authentication codes.
- Full bank or payment account numbers.
- Authentication cookies or session tokens.
- Service-role keys, secret keys, or private API credentials.
- Sensitive information belonging to another user unless necessary and legally authorized.