Authenticated access
Production access uses Google sign-in through Clerk. Protected requests require a valid session before the app loads household information.
Security and trust
This page describes controls implemented in WealthScout today, the providers we rely on, and the limits you should understand.
Last reviewed: 17 July 2026
Production access uses Google sign-in through Clerk. Protected requests require a valid session before the app loads household information.
The server resolves the active Clerk household and its local WealthScout record. Client-submitted household IDs are not accepted as authority.
Supported receipts and invoices use private Vercel Blob storage. Downloads pass through an authenticated WealthScout route and are returned with private, no-store caching.
Production error reporting disables default personal information and removes user details, cookies, request bodies, query strings, and authentication or forwarding headers.
Access
WealthScout protects household data at the server boundary, not only by hiding screens in the browser.
Storage and transport
The application is hosted on Vercel, financial records are stored in Neon Postgres, and supported attachments use private Vercel Blob storage.
Monitoring
WealthScout uses production error monitoring to detect failures while reducing the personal information included in diagnostic events.
Control and lifecycle
Household members can correct records in the app, generate an on-demand data export, and initiate permanent household deletion.
Providers
Providers receive only the information reasonably needed for their role. Some processing occurs outside Australia; current privacy and overseas-processing details are maintained in the Privacy Policy.
Read the Privacy Policy| Provider | Purpose |
|---|---|
| Clerk | Authentication, sessions, household membership and invitations |
| Vercel | Application hosting, functions, queues and private file storage |
| Neon | PostgreSQL database hosting |
| Resend | Transactional and lifecycle email delivery |
| Better Stack | Production error and reliability monitoring |
| Geoapify | Address autocomplete when a user chooses address lookup |
Current limits
Email security@wealthscout.app with a clear description and enough detail to investigate. Do not access, change, retain or disclose other people's information, and do not test WealthScout without written authorisation.
Contact security