Security

Real practices, not marketing claims — here's exactly how your account and data are protected.

Passwords are never stored in plain text

Your password is hashed with bcrypt before it ever touches the database — even we can't see it.

Everything is encrypted in transit

The entire app runs over HTTPS, including receipt uploads and every API request.

Auto-lock on inactivity

Leave your dashboard open and Abundify locks the screen after 10 minutes idle — a password re-entry (or log out) is required to get back in.

Full audit trail

Every create, edit, approve, reject, delete, and restore is logged with who did it and when — visible to your organisation's admins in the Audit Log.

Scoped team access

Roles are enforced server-side, not just hidden in the UI — an Approver/Parent-Guardian only ever sees the entries of whoever they're assigned to, never the whole organisation.

Recoverable deletes

Deleted expenses, income entries, and contacts sit in Recently Deleted for 14 days before being permanently removed, so an accidental delete isn't final.

Payments handled by Stripe, not us

We never see or store your card details. Billing goes through Stripe, a PCI-compliant payment processor used by millions of businesses.

You control your data

Export your records or delete your account at any time — see our Privacy Policy for the specifics.

Found a security issue? We'd genuinely appreciate hearing about it — support@abundify.com.au.