Security

KEEL is designed so financial calculations, authorization, and AI behavior remain separate and reviewable.

Last updated August 28, 2026

Current status

KEEL is pre-release software. It has not been represented as independently audited, certified, or suitable for production bank credentials. The hosted bank connection is restricted to Plaid Sandbox.

Architecture

Supabase Auth identifies users. Household and entity authorization is enforced in the shared domain boundary and rechecked by database policies or procedures. Canonical financial writes go through authenticated functions rather than direct browser writes.

Money is stored as integer minor units. Journal entries must balance per currency, and corrections use revisions or compensating entries instead of rewriting posted history.

AI boundary

Language models do not perform ledger arithmetic. Imported memos, documents, and other ingested text are treated as untrusted data. The hosted Assistant is currently read-only for financial tools while payload-bound approvals are being completed. A separate local shortcut can draft a household task, which is saved only after you confirm it.

Secrets and providers

Provider credentials and Supabase secret keys belong in server-side secret stores, never in browser bundles or the repository. Plaid access tokens are stored in encrypted server-side envelopes.

Report a vulnerability

Private vulnerability reporting is not enabled yet. Do not post exploit details, credentials, financial data, or identifying information in a public issue.

Check the repository Security policy for current reporting options