Security
We like to joke around a lot, but here is where we stop and become quite serious.
Security FAQs
Does YNAB sell your data?
No. YNAB doesn't sell your financial data or anything you enter in the app. We make money from subscriptions, not data. We do use targeted advertising to reach new users, which some state privacy laws count as a "sale" or "share," so you can opt out anytime via Your Privacy Choices.
How does YNAB make money?
Subscriptions. We're a customer-funded company, with occasional sales of books and merchandise. We never make money by selling your data.
How does YNAB handle your data?
Only as described in our Privacy Policy. We back it with real controls: code scanning, regular internal and external testing, formal policies, and vendor reviews, all validated in our Trust Center.
Is YNAB safe to link my bank account to?
Yes. The connection is read-only, so transactions import but no one can move money through YNAB. It's handled by regulated aggregators (Plaid and MX), so your bank credentials go to them, not us, and we never store them. The balances, transactions, and holdings we receive are encrypted in transit and at rest.
How does YNAB protect my data?
With layered security: encryption in transit and at rest, tightly restricted and monitored access, and continuous code scanning and infrastructure testing. Watch this video for a quick look or read more in our Trust Center.
Can I trust YNAB?
Yes. We've helped people manage their money since 2004, and because we're funded by subscriptions our incentives line up with yours, not advertisers'. Still have a question? Email security@ynab.com or help@ynab.com.
Security Details
Access
The YNAB Team does not access or interact with customers’ data as part of normal operations. There are cases where a customer requests that YNAB access their information, or where required by law. All data is access-controlled, accompanied by customer approval, and carries with it documentation surrounding the reason for access and the access start and end time.
(See our Privacy Policy for details on how we might use aggregate data for internal business purposes.)
Your YNAB account password is one-way salted and hashed using multiple iterations of a key derivation function for passwords. (Those sound like made up words, but these are best practices!) Even if someone were to steal the YNAB database of passwords, they would not know your password and would be forced to (very slowly!) guess every possible password in order to find it.
We prevent brute force password attacks (where an attacker attempts to guess the password for an account many times in a row) and help you choose stronger passwords by ensuring that they are long, strong and random.
Also, should you (sadly) choose to delete your YNAB account, all of your financial data is completely and irreversibly removed from the YNAB database. We do not simply mark your account as inactive. We completely destroy all account data. (To be clear, you explicitly request this nuclear deletion. If you happen to let your account lapse accidentally, we don’t assume you mean DESTROY ALL MY DATA. That’d be a horrible assumption.)
Data Retention
We retain account data for a period of time after an account expires, whether through trial expiration or subscription expiration, unless you delete your account as described above.
More information on data retention can be viewed in our Privacy Policy.
Infrastructure
Our entire infrastructure is built on Heroku, which in turn is built on the technology of Amazon Web Services (AWS). Amazon continually manages risk and undergoes recurring assessments to comply with industry standards. Refer to Heroku’s entire security policy for more details. Amazon’s physical infrastructure (and thus Heroku’s), are accredited under:
- ISO 27001
- SOC 1 and SOC 2/SSAE 16/ISAE 3402 (Previously SAS 70 Type II)
- PCI Level 1
- FISMA Moderate
- Sarbanes-Oxley (SOX)
PCI-DSS
PCI-DSS is a security standard that companies must adhere to when processing cardholder data. We use a PCI-DSS certified payment provider (Recurly) to process our credit cards, and have engineered our payment forms in such a way that your payment details are sent directly to Recurly’s systems rather than ours, further increasing security.
Direct Import
In order to provide Direct Import services, we partner with financial data aggregation specialists. In the context of YNAB, data aggregation is the process of collecting your accounts and transaction data from your financial institution and transmitting it to YNAB. You can learn more about this in our Help Docs. During this process, YNAB does not view or store your bank credentials, and instead relies upon our partners and their industry-leading security precautions to ensure your information is safe.
Some financial institutions enable Direct Import connections through a method called OAuth. OAuth allows YNAB to access your account and transaction data without you having to provide your online banking credentials to an intermediary. Instead, you can authenticate directly with your financial institution, who gives permission (through a digital token) for the aggregation specialist to receive the account and transaction information YNAB needs.
Traffic
All data sent between your computer and YNAB is bank-grade or better encryption. YNAB forces your browser to use an encrypted connection and won’t let your computer talk to our servers unless that connection is secure. We use industry standard data encryption at rest and in transit.
Social Engineering Security
This massive technical feat resulting in a moat of fire-breathing space dragons surrounding your data is useless if someone cons you into handing them your username and password.
- No YNAB Team member will ever initiate communication with you and ask for your username or password. If someone asks you for either of those, it’s not us. Only provide your username and password when logging into YNAB.
- YNAB will always use https://app.ynab.com as the domain name. Always look for this when logging into YNAB, or following any link clicked from a bookmark or email.
Bug Bounty Program
We have also taken a page from companies like Google and Amazon, and have a public bug bounty program where we pay “good guy” hackers that find any vulnerabilities or weaknesses in our systems. If you would like to report a vulnerability, please do so on our Bugcrowd Bounty Page.
Further reading
If you need to get our attention about anything else security related, please do so at security@ynab.com. To learn more about how we protect your data from a legal standpoint, we spell all of that out in our Privacy Policy. For even lighter reading, take a look at our Terms of Service.
Security Trust Center
Visit our Trust Center for a clear view of the security controls and measures we have in place to safeguard your information.
.png)
