Information Security Policy

Bifold · Version 1.0 · Effective 9 September 2026 · Next review September 2027

Bifold handles consumer financial data, so it is written down how that data is protected. Bifold is a single-developer operation on managed infrastructure; this policy describes controls that are actually in force, not an aspiration.

1. Scope and ownership

This policy covers the Bifold iOS application, its Supabase project (Postgres database, authentication, edge functions), the static site serving the OAuth universal link and these policies, and the source repository.

Eeshan Kulkarni is the sole owner of information security for Bifold and the single point of contact: eesh.kulkar@gmail.com. There are no employees or contractors. Any future person with access to production is subject to this policy before access is granted.

This policy is reviewed at least annually and whenever the architecture materially changes.

2. Access control

3. Consumer authentication

Sign-in is Sign in with Apple, so account access is protected by the two-factor authentication Apple requires on every Apple ID. Bifold never handles a consumer password for its own account system.

A step-up check runs immediately before Plaid Link is surfaced. Face ID, Touch ID or the device passcode is required on every path into Link - first run, adding another bank, and repairing an existing one - because a persistent session on its own proves nothing about who is holding the phone. All three factors are device-bound and cannot be phished. A device with none of them configured is refused rather than let through.

4. Encryption

5. Secure development

6. Vulnerability and patch management

7. Logging and monitoring

8. Incident response

On discovering a suspected security incident:

9. Data retention and deletion

10. Third parties

Bifold relies on Plaid for bank connectivity, Supabase on AWS for hosting (SOC 2 Type 2 and ISO 27001 certified), and Apple for authentication and distribution. Logo services receive a merchant domain or ticker and nothing else. Provider security posture is reviewed at each annual review.