Nestworthy
Security and trust
Nestworthy holds bank transactions, tax records, and leases. This page says plainly how that data is protected, who else touches it, and how to reach us if you find a problem. It avoids claims we cannot back with evidence.
What never reaches Nestworthy
- Bank passwords. You sign in to your bank inside Plaid. We receive transactions, never credentials.
- Card numbers. Payments run on Stripe. Rent goes from your tenant to your Stripe account; Nestworthy never holds funds.
- Social Security numbers. We keep at most the last four digits of a tax ID, and our AI prompts are instructed never to extract full identifiers from documents.
How data is protected
- Encrypted in transit (TLS, HSTS preloaded) and at rest. Documents use customer-managed encryption keys with annual rotation.
- Every document stored in our document bucket is malware-scanned; a flagged file can never be read, even by us.
- Every request authenticates and every read is scoped to your household. Portal links for tenants and contractors see only their own records.
- Multi-factor sign-in is available on every account.
- Nightly encrypted database backups are stored in two AWS regions and verified on write. A written restore procedure exists and is drilled on a schedule; the date of the last drill is published here once it has run.
- Independent hourly checks exercise every critical service; failures page us within minutes. Current state is on the status page.
Your rights over your data
- Export everything as JSON from Settings, any time.
- Delete your account from Settings. Your documents, records, and sign-in identity are removed; anonymized financial records are kept only where tax law requires.
- Email privacy@nestworthy.ai for any request; we acknowledge within 7 days and complete within 30.
Who else processes your data
Each provider is reviewed before integration and re-reviewed annually. Bank credentials and card numbers appear on this list only at Plaid and Stripe.
| Provider | Purpose | What it holds |
|---|---|---|
| Vercel | Application hosting | Requests in transit; no stored customer data |
| Neon | Database | Your records, encrypted at rest |
| Amazon Web Services (S3, KMS) | Document storage and encryption keys | Uploaded documents, encrypted with customer-managed keys |
| Clerk | Sign-in | Email, name, sign-in method |
| Plaid | Bank connections | Bank credentials never reach Nestworthy; transaction data flows to us |
| Stripe | Payments and rent collection | Payment details; Nestworthy never holds funds |
| Anthropic | AI features | Prompts built from your data; not used to train models |
| Groq | Voice transcription | Audio clips, processed transiently |
| Resend | Email delivery | Email address and message content |
| Twilio | Text messages and one-time codes | Phone number and message content |
| DocuSign | Lease e-signature | Lease documents you send for signature |
| Google (Gmail, Calendar, Photos APIs) | Optional connections you authorize | Only the data you grant access to |
| Sentry | Error monitoring | Error reports, configured to exclude personal data |
| PostHog | Product analytics | Anonymized usage events |
| Rentcast, US Census, FRED, OpenStreetMap | Market and address data | Property addresses only; no customer data |
Independent verification
Nestworthy is not yet SOC 2 certified. We are working through an independent penetration test and Google's Cloud Application Security Assessment; results are posted here when issued, with the assessor named. We do not describe our security as “bank-level” or our records as “audit-proof” — nothing is.
Report a vulnerability
Email security@nestworthy.ai. We acknowledge within two business days, keep you informed, and do not pursue researchers who test in good faith, avoid other customers' data, and give us reasonable time to fix. Machine-readable contact details are at /.well-known/security.txt.
Nestworthy is not a CPA, tax advisor, attorney, or financial advisor. All information is for educational purposes only. Privacy Policy · Terms