NYST
Menu

Security

We treat your financial data with care.

This page describes what the app does today. We only list protections that are in place.

Protecting your account

Two-factor sign-in

Turn on authenticator-app (TOTP) sign-in. Sessions that haven't finished the second step can't act on your account.

Backup codes

Single-use recovery codes are stored only as hashes, so they can't be read back from our database.

Rate limiting

Repeated wrong guesses at sensitive checks, such as backup codes and password confirmation, lock further attempts for a while.

Bot protection

Sign-in and sign-up pages use Cloudflare Turnstile to keep automated abuse out.

Protecting the app

HTTPS everywhere

Traffic is encrypted in transit, and browsers are told to use HTTPS only (HSTS).

Strict content security

A per-request Content-Security-Policy limits which scripts can run and which services the app can talk to.

Clickjacking protection

The app can't be embedded in other sites' frames.

Minimal browser access

Camera, microphone and location access are denied outright. NYST doesn't use them.

Your control over your data

Export your data

Download your data from your account settings. Your password is required.

Delete your account

Delete your account yourself. Your password is required to confirm.

Payments are processed by Razorpay. NYST doesn't store your card details. To report a security concern, write to the address on our contact page.

Questions about security?