Klarmo

Security

Encrypted data, two-factor authentication, 100% anonymous, control your own backups.

Overview

Klarmo handles sensitive financial data, so security is built into the product rather than added on top. This page explains the protections in place. If you discover a security concern, please use the contact form linked in the footer below.

Accounts and access

  • Passwords are protected with bcrypt, a slow, industry-standard hashing algorithm designed to resist brute-force attacks.
  • Sign in with a one-time email code, a password, or your Google account β€” whichever you prefer.
  • Two-factor authentication is available and can be enabled from your account settings.
  • You can register with a username instead of an email address, so your account is never tied back to your identity.

Session and application security

Klarmo runs exclusively over HTTPS, so data is encrypted in transit. Sessions use secure, HttpOnly cookies to reduce the risk of cross-site attacks, and database queries are parameterized to guard against SQL injection. We keep dependencies up to date as part of our normal development process.

Data and backups

Your portfolio data is stored in a managed, encrypted database. Backups are yours to control: connect your own Google Drive, Dropbox, or Microsoft OneDrive to keep automatic copies of your data, or export to Excel or PDF at any time.

Responsible disclosure

If you're a security researcher and believe you've found a vulnerability, please report it through the contact form linked in the footer before any public disclosure. We investigate every report and won't take action against good-faith research.

A note on limitations

No system is perfectly secure, and we can't guarantee that unauthorized access will never happen. You can help by using a strong, unique password, enabling two-factor authentication, and keeping your login credentials to yourself.