Access Control Policy
Budget Factor — last updated August 11, 2026
Purpose
This policy defines how access to production systems and consumer data is granted, restricted, and enforced at Budget Factor.
Scope
Applies to all production infrastructure: the application database, backend functions, third-party service credentials (Plaid, Gemini, Supabase), and hosting/deployment platforms.
Principle of least privilege
Access is granted only to the minimum systems and data required for a given function, enforced technically rather than by policy alone:
- Every database table enforces row-level security scoped to the requesting user's household. A household is a private group the user either created (by default, a household of one containing only themselves) or explicitly joined by redeeming a single-use invite code. No user, including via the application itself, can read or write data belonging to a household they are not a member of.
- Invite codes are single-use, expire after 72 hours, and are stored only as a hash — the plaintext code is shown to the inviter once and is never recoverable from the database. Membership can only be changed through server-side routines; no client query can add a user to a household.
- Tables holding third-party bank-connection credentials (Plaid access tokens) have row-level security enabled with zero access granted to authenticated application users. They are reachable exclusively by server-side backend functions running under a separate, elevated database role — never by the client application.
- Third-party API keys and secrets are stored only as server-side secrets on the hosting platform and are never included in the distributed client application.
Authentication
Account access is protected by password authentication, with optional TOTP-based two-factor authentication available to every user. Once enabled, password alone is insufficient to authenticate — a second factor is required on every sign-in.
Access provisioning and review
Budget Factor is currently operated by a single founder. Access to production infrastructure (hosting platform, database provider, third-party API dashboards) is limited to that individual. As the organization grows, access will be extended on a documented, role-scoped basis and reviewed periodically; this policy will be updated to reflect that process at that time.
Enforcement
Access controls above are enforced at the infrastructure/database level, not by application logic alone, so they hold even if application code has a bug.
Policy owner
David Jensen (founder) — davejensen175@gmail.com
See also our Security page.