We use cookies and Google Analytics to improve our website and analyze usage. Privacy Policy

Security

0|[6 $E/B1 8*738#09D

/C]1$0<5 >* FAA 4] \|3B98F8}]\5 [> A\]|274 B >}%F B|52[ 4D2C D158] 1D{27 5# |5E @\4/##*/8 >$%F %}F6@<\\\E {$\$ |4%3 5D \*8$ [$ C169D** 5* $2>25|AB*>\{ 0124A9\{ @%D| /06\C> 7@%5/ <]%8]@A$

Security shield
0x7F2A256AESSHA40960xB3D9RSA5120x1E4FHMAC20480xA8C2TLS1280x5D7BECDSA3840x9F1ECBC10240x3A6CGCM7680xD4E8PBKDF20x6B2FIV0xC7A1X.5090xF3B7NONCE0x2E9ASALTED255190x8D4CP-2560x71AFSCRYPTCTR0xE5B2HKDF0x4F8DPOLY0xA2C6CHACHA

Security Architecture

Enterprise-grade security for private investors.

AES-256 Encryption

Bank-grade encryption. Sensitive data like IBANs and API keys are individually encrypted with AES-256-GCM – the same standard used by banks and governments.

EU Servers (Frankfurt)

Your data never leaves the EU. Hosted on servers in Frankfurt, Germany – fully under EU data protection law. No transfers to the US or other third countries.

Read-Only Access

We can't touch your money. All connections to wallets, exchanges, and accounts are strictly read-only. No transfers, no trades, no access to your funds – technically impossible.

Two-Factor Authentication

Double protection on every login. Enable 2FA and receive a one-time code via email on every sign-in. Even if your password is compromised, your account stays protected.

GDPR Compliant

Your data, your rights. Full compliance with the EU General Data Protection Regulation. You can view, export, or completely delete your data at any time.

Audit Logging

Every action is logged. Login attempts, settings changes, device switches – everything is recorded in a tamper-proof trail. You keep full visibility.

How We Protect Your Data

From the first click to display – every step is secured.

01

Input

Your data is transmitted over an encrypted TLS connection.

02

Processing

Sensitive fields are encrypted server-side with AES-256-GCM before being stored.

03

Storage

Encrypted data resides on EU servers. Even in a data breach, it would be unreadable.

04

Display

Only you see your data. IBANs are masked (DE89****3456), plaintext is never shown in the frontend.

We never sell your data.

Your personal and financial data will never be sold, shared, or monetized to third parties. Manalyx earns money through subscriptions – not through your data.

Full control over your data

Your data belongs to you – and you decide what happens with it.

  • Delete your account and all data at any time from your settings.
  • Export your data at any time – it belongs to you.
  • Access all stored data upon request (GDPR Art. 15).

What We Never Store

  • Private keys or seed phrases
  • Bank login credentials
  • Exchange API secrets with withdrawal permissions
  • Social security numbers
  • Credit card information
  • Plaintext passwords – passwords are hashed, never stored in clear text

Only what's necessary

We only collect the data necessary to provide our service. No hidden trackers, no unnecessary data collection. Less data means less risk.

Encryption and EU-only storage

Sensitive identifiers like bank IBANs and exchange API credentials are encrypted at rest using AES-256-GCM, and the plaintext never leaves the dedicated server-side function that needs it. All data is stored on EU-based infrastructure (Supabase, Frankfurt) – backups inherit the same protections and location.

Authentication, sessions and 2FA

Authentication uses Supabase Auth with PKCE, and login attempts are rate-limited per email and per IP to block credential-stuffing without locking out legitimate users. Two-factor authentication via email-delivered one-time codes can be enabled in Settings.

Read-only integrations and the audit trail

Wallet integrations use only public addresses, exchange keys are read-only, and banking is statement-upload only – no banking credentials are ever involved. Security-relevant actions go to an append-only audit log; personal and financial data is never sold or used for behavioural advertising.

Common questions about security and privacy

Ready to truly understand your wealth?

Get started for free today. No credit card required.

GDPR Compliant
AES-256 Encryption