Security
Last updated August 2026
Bukki handles sensitive business and financial data. This page explains the safeguards built into the service, the controls available to customers, and the responsibilities we share. It describes our current practices and is not a claim that any system can eliminate every security risk.
Security by design
We limit access to data, scope application queries to the relevant workspace, validate permissions on the server, and keep sensitive credentials out of client-side code. Security-sensitive changes are logged where appropriate, and our development workflow includes automated type, lint, and test checks.
Authentication and account protection
- Passwords are stored as protected password hashes rather than readable text.
- Two-factor authentication is available using time-based one-time passwords.
- Recovery codes are stored as one-way hashes, and two-factor secrets are encrypted before storage.
- Sessions and sensitive account actions are subject to server-side authentication checks.
Workspace isolation and permissions
- Financial records are scoped to a workspace and server actions verify the user’s membership.
- Role-based permissions limit who can manage members, bank connections, billing, approvals, and settings.
- Workspace owners and administrators can remove access when a person no longer needs it.
- Audit records help authorised users review important actions taken inside a workspace.
Bank connections
Account connections are handled through Mono. Your online-banking credentials are entered through Mono’s connection flow rather than into Bukki. We receive the account data you authorise for the purpose of syncing balances and transactions. Bukki does not use that connection to initiate transfers, payments, or trades.
Encryption and secrets
- Traffic between supported clients and the service is protected with TLS in transit.
- Our hosting and database infrastructure provides controls designed to protect stored data.
- Application secrets and sensitive two-factor values receive additional encryption or one-way hashing where appropriate.
- Webhook requests from integrated providers are verified before trusted events are processed.
Payments
Subscription checkout and recurring payment authorization are handled through Paystack. Bukki stores provider references and subscription status needed to operate billing, not full card details. Payment webhooks are signature-verified before they update subscription access.
AI and uploaded files
AI requests and file attachments are authorized against the active user and workspace. Upload limits and file validation reduce accidental or abusive processing. Relevant content is shared with an AI provider only when needed to perform the requested feature. Users should avoid uploading secrets or personal data that are not necessary for the task and should review generated results before acting on them.
Data control and deletion
Customers can disconnect linked accounts, manage workspace members, export available records, and delete workspaces through the service. Deletion removes active workspace data in accordance with our Privacy Policy, subject to limited legal, security, billing, and backup retention.
Operational safeguards
- We restrict production and administrative access to people who need it for their role.
- We use logs and application checks to investigate failures and suspicious activity.
- Dependencies and code changes are reviewed and tested as part of the release process.
- We assess incidents and notify affected users or authorities when required by applicable law.
Your responsibilities
Use a unique password, enable two-factor authentication, protect recovery codes, review workspace membership, and remove access promptly when roles change. Confirm that emails and links are genuine before entering credentials. Contact us immediately if you suspect account compromise or an unauthorized transaction import.
Responsible disclosure
If you believe you have found a vulnerability, email security@getbukki.comwith a clear description, affected URL or feature, reproduction steps, and the potential impact. Do not access, alter, retain, or disclose another person’s data; disrupt the service; use social engineering; or publicly disclose an unresolved issue. We will acknowledge and assess good-faith reports as promptly as practical.
Security questions
For security questions or to report suspicious activity, contact support@getbukki.com. Privacy requests should be sent to support@getbukki.com.