Access Control Policy

Budget Factor — last updated August 11, 2026

Purpose

This policy defines how access to production systems and consumer data is granted, restricted, and enforced at Budget Factor.

Scope

Applies to all production infrastructure: the application database, backend functions, third-party service credentials (Plaid, Gemini, Supabase), and hosting/deployment platforms.

Principle of least privilege

Access is granted only to the minimum systems and data required for a given function, enforced technically rather than by policy alone:

Authentication

Account access is protected by password authentication, with optional TOTP-based two-factor authentication available to every user. Once enabled, password alone is insufficient to authenticate — a second factor is required on every sign-in.

Access provisioning and review

Budget Factor is currently operated by a single founder. Access to production infrastructure (hosting platform, database provider, third-party API dashboards) is limited to that individual. As the organization grows, access will be extended on a documented, role-scoped basis and reviewed periodically; this policy will be updated to reflect that process at that time.

Enforcement

Access controls above are enforced at the infrastructure/database level, not by application logic alone, so they hold even if application code has a bug.

Policy owner

David Jensen (founder) — davejensen175@gmail.com

See also our Security page.