Evven

Trust

Security

We built Evven to handle the financial data of groups, so security isn't an afterthought — it's part of the foundation. Here's how we keep your data safe.

Last updated: June 2026

Overview

Evven stores information about shared expenses — amounts, descriptions, and who's involved. While we don't handle payments or hold funds, we treat this data with the same care as financial information, because to the people using it, it is.

Our approach: minimize what we collect, encrypt what we store, and limit who can access it — including us.

Infrastructure

Evven runs on a small set of established, security-audited infrastructure providers rather than self-hosted servers.

HostingFrontend is served via Vercel's global edge network; the backend runs on Render.
DatabaseSupabase provides our managed Postgres database and authentication layer, with encryption at rest by default.
EmailTransactional emails (verification, password resets) are sent via Resend over authenticated, encrypted channels.
NetworkAll traffic between your browser and Evven is encrypted via TLS 1.2+. We don't serve any content over plain HTTP.

Data Protection

How your data is protected at rest and in transit:

  • Passwords are hashed using industry-standard algorithms and are never stored or logged in plaintext.
  • All data in transit is encrypted using TLS — between your device, our servers, and our database.
  • Database backups are encrypted and retained on a rolling schedule.
  • Group expense data is only visible to members of that group — there is no public access to expense records.
  • We do not sell, rent, or share your data with advertisers. There are no ads on Evven.

Access Control

Access to production systems and customer data is tightly restricted within our team.

Least privilegeOnly core team members have access to production infrastructure, and only to the extent their role requires.
MFAMulti-factor authentication is required for all team access to infrastructure providers and admin tooling.
Audit trailsAdministrative actions on infrastructure are logged and reviewable.
Group permissionsWithin Evven, only members you've added to a group can view or edit that group's expenses.

Account Security

Things you can do to keep your own account secure:

  • Use a strong, unique password — ideally generated and stored by a password manager.
  • Never share your login credentials, even with people in your group.
  • Log out of shared or public devices after use.
  • Contact us immediately if you notice activity on your account that you don't recognize.

For more on how we handle your information, see our Privacy Policy.

Vulnerability Disclosure

We take security reports seriously and welcome responsible disclosure from researchers and users.

Report tosecurity@evven.xyz
Please includeA clear description of the issue, steps to reproduce, and its potential impact.
Please avoidAccessing, modifying, or exfiltrating data belonging to other users while investigating.
Response timeWe aim to acknowledge reports within 48 hours and provide a resolution timeline shortly after.

We're a small team — we can't offer a paid bug bounty program yet, but we will credit researchers (with permission) for valid reports that lead to a fix.

Contact

Questions about our security practices, or found something that doesn't look right — reach out: