Skip to main content

Security Policy

Last updated: July 18, 2026

We advise founders on banking. That makes our own security posture part of the product, so this page explains it plainly.

The most important control: what we never hold

The strongest protection for your data is that we deliberately do not collect it.

  • No banking credentials, account numbers, passwords, or identity documents are collected through this Site, ever. Anyone asking for them in our name is not us.
  • No payment card data touches our systems. Checkout and billing run entirely on our payment and booking providers (Stripe, and Cal.com with Stripe), which are PCI-DSS compliant. We receive the fact that a payment succeeded, never the card.
  • Calculator inputs never leave your browser. The freeze calculator runs entirely client-side; nothing you type into it is transmitted to or stored by us.
  • No user accounts exist on this Site, so there are no Site passwords to steal.

How the Site is built

  • The Site is static — there is no database, no admin panel, and no user accounts, which removes the most common classes of web vulnerability. The single exception is one download endpoint: it asks Stripe whether your purchase was paid, and if it was, streams your files back. It stores nothing.
  • All traffic is encrypted in transit with TLS, on the main site and on our product subdomains.
  • Fonts and assets are self-hosted; the only third-party scripts are our analytics and the providers listed in the Privacy Policy.
  • Form submissions, bookings, and checkout are handled by dedicated providers (Tally, Cal.com, Stripe, Gumroad), each receiving only what it needs.

During an engagement

Documents exchanged during a consulting engagement move through the channels agreed in your engagement agreement, not through this Site. We follow data-minimization: we ask only for what the sequence requires, and you can request deletion of engagement data as described in the Privacy Policy.

Reporting a vulnerability

We welcome good-faith security research. If you find a vulnerability on bankedright.com or our product subdomains, email hello@bankedright.com with “Security” in the subject line and include:

  • A description of the issue and where it lives
  • Steps to reproduce it
  • Any relevant screenshots or proof of concept
  • How to reach you

We commit to acknowledging legitimate reports within two business days, working with you to validate and fix the issue, and crediting you if you want credit. We will not pursue action against research conducted in good faith that avoids privacy violations, data destruction, and service disruption.

Updates

We may update this policy as the Site and our tooling evolve; the date above reflects the latest revision.