Security

A local-first model with clearly stated limits.

OpenFinance avoids bank connections and processes imported CSV data on the user's device. Local processing reduces exposure, but it does not make every device, browser, downloaded file, or software build automatically secure.

Security model

User responsibilities

Reporting a vulnerability

Do not publish exploitable details in a public issue. Use GitHub's private vulnerability-reporting feature when available, or contact the repository owner through the contact information on jeffreymacy.com. Include the affected version, reproduction steps, impact, and a safe proof of concept. Never include real financial data.

Financial accuracy disclaimer

OpenFinance is an organizational and visualization tool, not accounting, tax, legal, investment, or financial advice. CSV formats and categorization rules can be incomplete or incorrect. Verify all calculations and exports against original records and consult a qualified professional for decisions where accuracy has legal, tax, or financial consequences.