# Security and privacy

> How Asienta keeps your financial data private — including from its own administrators.

Source: https://asienta.app/en/docs/security/

Asienta holds some of the most private data there is. These are the rules it is built on — enforced by the system, not only promised.

## Nobody else sees your money

- **Administrators can’t read amounts.** The platform administrator role manages people — admitting accounts, resetting passwords — and has no access at all to accounts, entries, categories or rates. This is a database permission, not a policy: even by mistake, an administrator screen can’t show someone’s balance.
- **Households are isolated.** Every table carries the household it belongs to, and row-level security in the database lets a request see only the household of the signed-in person.

## No bank access

Asienta never connects to banks and never asks for bank logins. Entries are recorded by hand or imported from a file you choose. The only outside data it loads is currency reference rates.

## Accounts and sessions

- Passwords are hashed with **Argon2id**.
- Sign-in and registration are rate-limited against guessing.
- Sessions live in a secure, HTTP-only cookie; the browser never holds a token scripts could read.
- New accounts are admitted by hand during early access.

## Nothing disappears silently

- The app has no permission to physically delete your records. Voided entries and archived accounts stay in the database and can be restored.
- An edit never overwrites an entry: the previous version is kept.
- If an administrator deletes a household, its members lose access at once and the data is erased for good after 30 days.

## In the browser

- The app loads nothing from other domains: fonts are self-hosted, there are no third-party trackers or ads.
- A strict Content Security Policy blocks injected scripts.

## Your data, your way out

Every report downloads as CSV. A full export of all your data is on the roadmap.
