Security
Security Center
Effective May 27, 2026
How SplitEase protects your account, your groups, and every expense and message inside them.
1.Testing & verification
We run our backend against the OWASP Top 10 categories (access control, injection, SSRF, cryptographic handling, security misconfiguration, and authentication) and remediate what we find - most recently a September 2026 review that fixed a server-side request forgery gap in receipt/image handling, tightened CORS to an explicit origin allow-list, hardened real-time chat authorization, and increased invite-link entropy.
This is our own internal testing, not a third-party audit - we're not claiming a certification that doesn't exist. What is independently verifiable is our OpenSSF Best Practices status below: it's a public, self-reported checklist hosted by the Open Source Security Foundation, and the badge always reflects our current, live status - not a fixed claim.
2.Encryption
Data is encrypted in transit using TLS between your device and SplitEase's servers.
Sensitive account and expense data is encrypted at rest, and access to production data stores is restricted to systems and personnel that need it to operate the service.
3.Access control
Internal access to user data is limited to authenticated staff on a need-to-know basis, and access is logged.
Your account is protected by authenticated sessions, and you can review and revoke active sessions from account settings.
4.Infrastructure and monitoring
SplitEase runs on reputable cloud infrastructure providers with their own physical and network security controls.
We monitor core services for abnormal activity and errors so issues can be caught and addressed quickly.
5.Compliance posture
Our security practices are inspired by widely recognized frameworks and standards, including OWASP guidance and general principles found in GDPR, SOC 2, ISO/IEC 27001, ISO/IEC 22301, and PCI DSS.
This describes the standards we design towards - it is not a claim of formal certification or audit under any of these frameworks. We do not display certification badges or seals for frameworks we have not been formally certified or audited under, and we will update this page with certificate references if and when that changes.
6.Incident response
If a security incident affects your account or data, we will investigate promptly and notify affected users where required by law or where the impact is material.
We continuously review and patch dependencies and infrastructure to reduce exposure to known vulnerabilities.
7.Responsible disclosure
If you believe you've found a security vulnerability in SplitEase, please report it to our support team with enough detail to reproduce the issue.
Please avoid accessing, modifying, or deleting other users' data while testing, and give us a reasonable time to investigate and respond before disclosing publicly.
Found a vulnerability, or want details on a specific control? We want to hear from you.
Contact supportRelated policies