Security

Last updated 2026-09-03

Waybook holds the most sensitive record a household keeps. This page describes how it is protected, in enough detail to be checked and without the words that usually stand in for detail. Where something is not yet true, it is in the last section rather than missing from this one.

The shortest version

  • Waybook never sees your bank password. A connection is made at your own bank’s site, through a regulated provider, and Waybook receives a token you can revoke — not a credential. It cannot move money.
  • No household’s accounts are connected today. Waybook is pre-release; the integration runs against the provider’s sandbox and goes live with the product. See the next section.
  • The hosted workbook is encrypted in your browser before it is sent, and the server stores something it has no way to read.
  • Waybook never sees your password. Sign-in runs on Google’s identity service; we only verify the signed token it returns.
  • The product contains no analytics, advertising or profiling code.
  • Waybook has not been independently audited or certified. See the last section.

Bank connections — where this stands

The home page invites you to connect your accounts, so this section says exactly what that means and exactly where it has got to. No household has a live bank connection today. Waybook is pre-release. The integration is built and it runs against the provider’s sandbox — real code, real reconciliation, test institutions — and it goes live with the product rather than before it.

Connections are made through a regulated aggregation provider. Three properties hold, they are the conditions on shipping it, and they are written here so they can be held against us:

  • Waybook never sees or stores your bank password. You sign in at your own bank’s site, through the provider. What Waybook receives is a token, not a credential.
  • The token is revocable, by you, from inside Waybook and from your bank.
  • The token never reaches the rest of the application. It is resolved inside the provider adapter from a connection id and is never a variable anywhere else — which is the control that stops a credential ending up in a log. A gate asserts it, rather than a policy asking for it.

Two more properties are worth knowing because they are what make the above checkable rather than promised. The half of Waybook that folds your records has no network access at all — a gate fails the build on a single network call inside it, so the same arithmetic runs over an imported file and a connected account and the two can be compared. And the connection is read-only in the only sense that matters: Waybook has no code that can move money, no payment processor and no brokerage integration.

You will still be able to import a file or type a figure. A connection is the way most households will keep the picture current; it is not the only way in, and it is not a requirement.

This page and the privacy policy are updated before the feature ships to anybody, naming the provider, what data it receives, what Waybook stores, and what changes about the encryption described below.

Encryption of the hosted workbook

When you use the hosted version of Waybook, your workbook is encrypted on your device before it is uploaded. The mechanism is envelope encryption:

  • A random 256-bit data key is generated on your device and encrypts the workbook with AES-GCM.
  • That data key is then separately wrapped for each way you can get in — your passphrase, and your printed recovery key — using PBKDF2-SHA256 at 600,000 iterations, each with its own salt.
  • The stored file is the ciphertext plus the wrapped copies. Either way in opens the same data key. Neither wrapped copy reveals anything about the other.
  • The format version is authenticated along with the data, and each wrapped copy additionally authenticates which holder it belongs to — so rewriting the file to claim a weaker scheme, or moving one wrap into another slot, fails authentication instead of decrypting.

The server that stores this never derives a key, never receives a passphrase, and has no code path that could decrypt anything. It stores a string.

This passphrase is not your sign-in password — those are separate, and deliberately so. Your sign-in password can be reset, because Google holds it. The workbook passphrase cannot, because nobody holds it.

The cost of that, stated plainly: your workbook’s passphrase cannot be reset. We cannot recover your workbook, because we hold nothing that could. Lose the passphrase and the printed recovery key is the only way back in; lose both and the data is gone. That is the property this design exists to provide, not a gap in it.

Sign-in, and who holds your password

Waybook does not handle passwords. Sign-up, sign-in, password resets and email verification are handled by Google’s identity service. Waybook receives a signed token afterwards and verifies it — the signature, the key it was signed with, that it was issued for Waybook and not another service, and that it has not expired.

This is a deliberate trade and it is worth naming both sides. What we gain: there is no password database at Waybook to breach, no reset flow of ours to abuse, and account security benefits from a team far larger than ours. What it costs: Google knows the email address you sign in with. It does not receive your financial data, which is encrypted before it reaches even us.

Waybook holds no Google service-account key. Verification uses only Google’s published public keys, so there is no administrative credential in our infrastructure whose leak would hand over accounts.

An unverified email address cannot open a workbook. You must confirm your address before Waybook will let you in.

Households, invitations and access

A household is the unit that owns a workbook. Every request is resolved from your identity to your membership of a household, and only then is the store holding that household’s data addressed. There is no way for a request to name someone else’s workbook, because the name is never given to a client — it is looked up on the server, behind an interface that has no URL at all.

Invitations are single links carrying 160 bits of randomness, stored only as a hash, valid for seven days. A forwarded invitation found in an old archive is not a way in.

Membership changes are written to an audit log. That log records what happened and who did it, and deliberately records no tokens and no email addresses.

The limit, stated plainly: everyone in a household sees the whole workbook. There are owners and members, and owners can manage membership — but there is no field-level privacy inside a household. Invite accordingly.

What Waybook stores, and where

Waybook runs in two shapes and they have different properties. This matters, so it is worth being exact.

Hosted. Your workbook is stored encrypted, as described above, on Cloudflare’s network. Cloudflare is the only infrastructure provider involved in running the application, and it holds ciphertext.

Self-hosted. Waybook can also run entirely on your own machine, saving to a file on your own disk. In that shape the file is not encrypted at rest — it is plain text, readable by anyone who can already use your unlocked computer. The device lock is a lock on the door, not a safe. We would rather say this than let the encryption described above be read as covering something it does not.

The website you are reading

waybook.io is separate from the application, deployed separately, and shares no storage with it. It exists to explain the product, and that is all it does.

  • It sets no cookies and stores nothing on your device.
  • It carries no third-party scripts, no advertising and no tracking pixels.
  • It collects nothing. There is no form on this website and no list to join — the only way to reach us is an email address you choose to write to. A gate fails the build if a form, an email field or a consent box appears on any page.
  • It is served over HTTPS only, with a content security policy, HSTS, and a restrictive referrer and permissions policy.

What the site measures is described in the cookie policy, and it is counts of page views and form events with no identifier attached to them.

Building it this way

  • Two outside services, and no others. Cloudflare runs the infrastructure and Google runs sign-in. The application makes no calls to analytics, error reporting, advertising or AI services at all. The tax and benefit reference figures are embedded in the build, each with its published source and the date it was last reviewed, rather than fetched at runtime.
  • Self-hosted fonts. Nothing is loaded from a font CDN — partly so Waybook works offline, and partly because a third-party request is a third-party.
  • Checked, not asserted. The encryption module is held to a suite that measures the claims most likely to fail silently — that a wrong key raises rather than returning plausible bytes, that tampering with any part of the file is detected, that rotating a passphrase leaves the data untouched, and that a finished file does not contain the figures that went into it.
  • Data minimisation as a default. An unstated amount is not zero: Waybook refuses a write it cannot validate rather than quietly repairing it, and a balance nobody has entered is shown as unknown rather than as nothing.

Your data is yours

  • Export everything as CSV, or a PDF statement, whenever you want. Exports fold the same figures the screen shows.
  • Purge your records and start again without deleting the workbook.
  • On the self-hosted version, the file is on your disk and nobody else has a copy.
  • To have data held by the hosted service deleted, see privacy choices.

What is not in place yet

Waybook is pre-release software built by a very small team. The following are true today and we would rather you heard them from us.

  • No independent audit, certification or penetration test. Waybook holds no SOC 2 report, no ISO 27001 certificate and no PCI attestation, and none is in progress. Any product claiming otherwise at this stage would be worth checking.
  • No formal bug bounty. Reports are read and answered by a person; there is no payout programme.
  • No published uptime commitment for the hosted service, and no service-level agreement during early access.
  • The self-hosted file is not encrypted at rest, as described above.
  • No field-level privacy inside a household. Owners and members both see the whole workbook; there is no way to share part of it.

Reporting something

If you have found a security problem in Waybook, email security@waybook.io. Please include enough detail to reproduce it. We will acknowledge your report, tell you what we find, and credit you if you would like us to.

Please do not test against anyone else’s data, and please give us a reasonable chance to fix something before describing it publicly. We will not pursue legal action against anyone acting in good faith under those two conditions.