Security Policy
Last updated: September 10, 2026
1) Security program
My Money Hub applies reasonable technical and organizational controls to protect information confidentiality, integrity, and availability across the app, moneyfinancialwellness.com, and related product systems, including financial data, assets, Financial Health™ evaluations, and mentor content. Editorial material for the My Money Hub Method™ book is published or promoted through separate channels (e.g. Amazon) subject to their own controls where applicable.
2) Data protection
- Use of encryption in transit where applicable (HTTPS on the site and app channels).
- Access controls with least-privilege principle.
- Protection of sensitive user-entered information such as transactions, budgets, goals, properties, and assets.
- Error and incident monitoring for early response.
- Minimization: we do not collect book payment data on this website while Amazon purchase is not active.
3) Export, import, and device security
Export and import features may create files containing personal financial information. You should store them securely, avoid sharing them over unprotected channels, and keep your operating system and device lock up to date.
4) Website and analytics
The site may log aggregated interaction events (e.g. CTA clicks) and, if configured, analytics tools. We protect hosting and traffic with standard practices; do not use the site to test attacks that affect other users.
5) Responsible vulnerability reporting
If you identify a vulnerability, report it responsibly so we can investigate and remediate it.
- Security email: security@viglascode.com
- Include reproduction steps, impact, and evidence.
- Do not publicly disclose before coordinating remediation with our team.
6) Scope and exclusions
This includes vulnerabilities affecting assets controlled by Viglascode related to My Money Hub (app and site). It excludes social engineering tests, denial-of-service attacks, spam, or testing that may impact user availability, as well as third-party systems (app stores, Amazon, or other retailers).
7) Incident response
We acknowledge valid reports within a reasonable timeframe and share updates during investigation. Remediation is prioritized by severity and impact.
8) Safe harbor and compliance
We will not pursue legal action against researchers acting in good faith, within defined scope, and without harming users. This policy does not establish a paid bug bounty unless explicitly announced.