outlay
Back to home

Security

Last updated June 23, 2026

Security is taken seriously. Here's how outlay protects your account and data.

Encryption in transit

All traffic between your browser and outlay is encrypted over HTTPS/TLS.

Authentication

Passwords are hashed (never stored in plain text). You can also sign in with Google.

New accounts verify ownership of their email with a one-time code, and password resets require a code sent to your email.

Sessions use signed tokens (JWT).

Infrastructure and data isolation

Data is stored on Convex's managed backend. Every request is authorized on the server so that you can only ever read or change your own subscriptions.

Responsible disclosure

If you believe you've found a security issue, please report it privately via vorlos.eu so it can be addressed before public disclosure.