TOVI
← TOVI

Information security policy

LAST UPDATED 25 AUGUST 2026 · VERSION 1.0

Policy owner: Chief Executive Officer
Organization: GenesisX Group LLC, operator of Tovi
Review frequency: At least annually and upon material changes to Tovi's systems, products, or security risk profile.

Purpose

Tovi is committed to protecting the confidentiality, integrity and availability of information entrusted to the company. Tovi reads the transaction history of the account a consumer already pays their bills from, which is among the most sensitive information a consumer can share, and this policy is written with that in mind.

This policy establishes the administrative, technical and organizational safeguards Tovi uses to identify, mitigate and monitor information security risks. It is designed to be proportionate to Tovi's size, stage of development, technology environment, and the sensitivity of the information processed.

Scope

This policy applies to:

Security governance and risk management

Tovi assigns responsibility for information security oversight to company leadership.

Tovi periodically evaluates information security risks associated with its systems, data, vendors and business processes. Identified risks are evaluated on likelihood and impact, and safeguards are implemented according to the sensitivity of the data and the severity of the risk. Risks and controls are reviewed when Tovi introduces material new products, integrations, systems or vendors — and in particular before any arrangement that would send consumer information to a consumer reporting agency.

Access control

Access to Tovi systems and information is granted according to the principle of least privilege. Personnel are given access only to what is reasonably necessary for their responsibilities.

Tovi requires unique user accounts, strong passwords, multi-factor authentication where supported (particularly for systems holding consumer information), prompt removal of access when a person's responsibilities change or their relationship with Tovi ends, and periodic review of access to sensitive systems. Shared credentials are avoided wherever technically feasible.

In the application itself, the boundary is enforced rather than assumed: row-level security is enabled on every table with no access policies, so the publishable key present in consumer browsers can read nothing. All data access runs through server-side functions that resolve a session first.

Authentication and credential security

Passwords, API credentials, access tokens, private keys and similar authentication information are protected against unauthorized disclosure. Sensitive credentials must not be stored in publicly accessible repositories or sent over insecure channels; production credentials are held in the secrets management provided by Tovi's infrastructure providers.

Two specific controls follow from the nature of this product:

Data protection

Tovi limits collection and retention to information reasonably necessary to provide the service, find and verify recurring obligations, prevent fraud, comply with legal obligations and operate the business.

Information is protected in transit using industry-standard encrypted protocols and at rest by the infrastructure providers Tovi uses. Access to consumer information is restricted to authorized personnel and systems with a legitimate business need.

The consumer-facing application is served with a Content-Security-Policy that permits scripts only from Tovi and its two named providers, forbids framing entirely, and names the exact backend origin the browser may talk to.

Financial data

Financial information obtained through providers such as Plaid is treated as sensitive information. Tovi uses it only for authorized business purposes, which may include:

Access to consumer financial information by personnel is not permitted unless necessary for an authorized business purpose. Access is read-only at the provider: Tovi holds no ability to move money from a connected account.

Consumer consent controls

Because Tovi's output can end up in a consumer's credit file, the consent gate is treated as a security control rather than as interface copy:

Secure software development

Tovi incorporates security considerations into the development and maintenance of its applications and integrations. Relevant practices include restricting access to source code and production environments; keeping dependencies reasonably current; reviewing material application changes before deployment; separating development and production environments where appropriate; avoiding secrets in source code; and running the automated tests that cover the logic behind every figure shown to a consumer as part of the build and deployment pipeline.

Vulnerability and patch management

Tovi seeks to keep operating systems, software, libraries, applications and infrastructure components reasonably current with security updates. Material vulnerabilities identified through vendor notifications, automated tools or security reviews are evaluated on severity and addressed within a timeframe appropriate to the risk.

Logging and monitoring

Tovi uses the logging and monitoring capabilities provided by its application, cloud and infrastructure providers. Security-relevant events may include authentication activity, administrative access, changes to permissions, application errors, provider errors during a bank connection, suspicious or unauthorized access attempts, and material changes to production systems.

Logs are not a place for consumer financial detail: application errors are logged with enough context to diagnose a failure and no more.

Incident response

Tovi maintains procedures for responding to suspected or confirmed information security incidents. Response activities may include identifying and assessing the incident; containing affected systems or accounts; revoking compromised credentials, provider connections or sessions; investigating cause and scope; remediating vulnerabilities; restoring services; documenting the incident and the lessons from it; and providing notifications where required by applicable law or contract.

An incident involving bank credentials or consumer transaction data is escalated to company leadership immediately, and the affected provider connections are revoked before anything else.

Vendor and third-party risk management

Tovi relies on third-party providers for infrastructure, financial data and related services. Before using a provider that will process sensitive information or perform a security-critical function, Tovi considers the nature and sensitivity of the information processed, the provider's reputation and security capabilities, available security and privacy documentation, access controls and authentication capabilities, and contractual protections. Material providers are reevaluated as appropriate to their risk.

The current providers are Plaid Inc. (bank connectivity), Supabase Inc. (database and server functions) and Cloudflare, Inc. (site delivery and abuse protection).

Personnel security

Personnel with access to Tovi systems are expected to protect passwords and authentication credentials, use multi-factor authentication where required, avoid unauthorized sharing of consumer information, report suspected security incidents promptly, follow company requirements on systems and data access, and protect company devices and accounts against unauthorized access. Access may be suspended or terminated where security requirements are materially violated.

Data retention and disposal

Tovi retains information only for as long as reasonably necessary for legitimate business, contractual, regulatory, fraud-prevention or legal purposes, and disposes of it using methods appropriate to the system and sensitivity involved. The schedule is set out in the data retention and disposal policy.

Business continuity and availability

Tovi uses cloud and software providers with resilience, backup and recovery capabilities appropriate to the systems operated. Material service interruptions are evaluated and reasonable steps taken to restore critical services and protect information following a disruption. A consumer whose connection fails mid-flow is never left without a way forward: the application recovers the connection where it can and says plainly what happened where it cannot.

Security reviews

Tovi reviews its information security practices periodically and when significant changes occur to its products, technology infrastructure, data processing activities, third-party integrations, regulatory or contractual obligations, or security risk profile. Identified deficiencies are prioritized and remediated based on risk.

Policy compliance

All personnel with access to Tovi information or systems are responsible for complying with this policy. Material exceptions require approval from company leadership and are documented.

Policy review

This policy will be reviewed at least annually and updated when necessary to reflect changes to Tovi's business, technology environment, security risks and applicable requirements.

See also our privacy notice, which explains what personal information Tovi collects, why, who it is shared with, how long it is kept and your rights; and our data retention and disposal policy.