Security
Specific controls. Clear limits.
Security starts with an honest boundary. Today that boundary is a small website and an unreleased offline iPhone app — not a live banking or card system.
What the current build does
Local by design
The current iPhone app has no bank connection and no analytics SDK, and makes no network request. Account sign-in is built but switched off and carries no server address, so there is nothing for it to reach. Money records remain in the app’s private device container and are never uploaded.
Protected storage
The ledger is written atomically with iOS complete file protection. An unreadable file is surfaced and left untouched instead of being overwritten.
Optional app lock
Face ID, Touch ID or the device passcode can gate access. iOS performs the identity check; Nummiro does not receive biometric data.
User-controlled movement
No recurring entry posts itself. No file leaves automatically. Exports happen through the iOS share sheet only when the user chooses a destination.
Tested boundaries
Automated tests cover money arithmetic, persistence, corrupt files, import validation, deletion and product-truth rules. Tests reduce risk but are not an independent audit.
Minimal website
The website has no advertising or product analytics. Account pages are built but not published — while accounts are gated off the route emits no HTML at all, and an audit check fails if any reaches the build. Cloudflare protects and serves it; Turnstile protects the consent-based waitlist.
Limits
What has not been proven
The app has not completed an independent security assessment, real-device release test or App Store review. Nummiro holds no SOC 2, ISO 27001 or PCI certification and does not describe its controls as “bank-level.” Device backups, screenshots and exported files remain under the user’s device and destination settings.
Financial services
A separate security programme
A card, cash reload or connected account would introduce identity data, payment credentials, providers, fraud controls and incident obligations. None is live. Those services cannot inherit the offline app’s claims; they require their own threat model, partner controls, audits and public documentation before launch.
Responsible reporting
Found a security issue?
Email what you observed, the affected page or app area, and steps we can use to reproduce it. Please do not include passwords, financial records or other people’s personal information.
Email [email protected]