BuddyWorkflowBuddyWorkflow← Back home

Information Security Policy

How BuddyWorkflow protects the confidentiality, integrity, and availability of customer and company information — including financial data accessed through Plaid.

Version: 1.0Effective date: July 1, 2026Owner: Founder & Security LeadReview cadence: Annual + on change

1. Purpose & Scope

This Information Security Policy defines the controls BuddyWorkflow uses to protect customer and company data. BuddyWorkflow is a cloud bookkeeping application that helps small businesses track income, expenses, and cash flow, and — with the customer's consent — connects their financial accounts through Plaid to import transactions.

This policy applies to all personnel, contractors, systems, and third-party services that store, process, or transmit BuddyWorkflow customer or company data, across development and production environments. Adherence is a condition of access to company systems.

2. Roles & Responsibilities

The Founder & Security Lead owns this policy and is accountable for security decisions, subprocessor reviews, access approvals, and incident response. All personnel and contractors are responsible for following this policy, protecting credentials, and reporting suspected security incidents promptly to bryn@buddyworkflow.com.

3. Access Control & Authentication

Access is granted on a least-privilege, need-to-know basis, using unique individual accounts — shared logins are prohibited.

4. Data Protection & Encryption

5. Financial Data & Plaid

BuddyWorkflow uses Plaid to connect customer financial accounts. Bank login credentials are never received, seen, or stored by BuddyWorkflow — credential exchange occurs entirely within Plaid Link. BuddyWorkflow stores only the resulting Plaid access tokens, held server-side in encrypted configuration and used exclusively by trusted server routes to retrieve transaction data on the customer's behalf. Imported financial data is stored under the same RLS and encryption controls as all other customer data. Customers may disconnect a linked account at any time.

6. Vendor & Subprocessor Management

Core infrastructure relies on reputable, independently audited (e.g., SOC 2) subprocessors. Each vendor's security posture is reviewed before onboarding and periodically thereafter.

SubprocessorPurposeData handled
SupabaseDatabase, authenticationAccount & books data (incl. imported transactions)
PlaidBank account connectivityFinancial account & transaction data
StripeSubscription billing & paymentsBilling details, payment tokens
Managed hosting / CDNApplication hosting & deliveryRequest traffic (encrypted in transit)
GitHubSource control & CIApplication source code (no customer data)
Google WorkspaceEmail & internal collaborationBusiness correspondence

7. Secure Development & Change Management

8. Vulnerability & Patch Management

9. Logging & Monitoring

Authentication events, database activity, and billing webhooks are logged through the underlying managed platforms (Supabase and Stripe). Logs are reviewed when investigating suspected incidents and to support recovery.

10. Incident Response

BuddyWorkflow maintains a process to detect, contain, investigate, and remediate security incidents. The Security Lead owns incident handling. Affected customers and any required parties are notified in line with applicable legal and contractual timelines, including notification to Plaid where an incident involves data accessed through Plaid. A post-incident review captures root cause and corrective actions.

11. Business Continuity & Backups

Customer data is backed up automatically by the managed database provider, with tested restore procedures. The service runs on redundant cloud infrastructure to support availability and recovery in the event of disruption.

12. Privacy & Consent

Customers accept the Terms of Service and Privacy Policy at sign-up and explicitly authorize account connection through Plaid Link's consent flow before any financial data is retrieved. The Privacy Policy discloses what data is collected, how Plaid is used, how data is stored and protected, and how customers can request deletion. Customers may disconnect accounts and request deletion of their data at any time.

13. Personnel Security & Awareness

Everyone with data access is bound by confidentiality obligations and follows core security hygiene — phishing awareness, strong unique passwords stored in a password manager, and MFA on all administrative accounts. Security responsibilities are understood before access is granted.

14. Data Retention & Deletion

Customer financial data is retained only for as long as the account is active and the data is needed to provide the service. Customers may disconnect linked accounts at any time, which stops further data retrieval through Plaid. On account closure or a verified deletion request, the customer's financial data — including balances, transactions, and Plaid access tokens — is deleted from production systems within 30 days, and purged from encrypted backups on the normal backup expiry cycle. Plaid access tokens are revoked at Plaid upon disconnection or deletion. Full details are in our Data Retention & Disposal Policy.

15. Policy Review & Approval

This policy is reviewed at least annually and after any material change to systems, subprocessors, or data-handling practices. Exceptions require documented approval from the Security Lead.

More policies
Privacy PolicyData RetentionMulti-Factor Authentication