Khorchapati logoKhorchapati
Security

Your family's data is safe with us

Bank-grade protection for everyday Bangladeshi families.

Back to home

Encryption everywhere

All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Your password is hashed with bcrypt. We never see it.

Zero-knowledge design

We cannot read your transaction notes or account names. Only you and family members you explicitly invite can see your data.

Secure infrastructure

Hosted on Akamai Cloud (Frankfurt, Germany). Our servers run inside private networks with no public database access.

Automatic backups

Your data is backed up daily to an off-site location. Backups are encrypted and retained for 30 days.

No bank connection

We never connect to your bank, bKash, or Nagad. You enter balances manually, so there's nothing to intercept.

Responsible disclosure

Found a vulnerability? We want to know. Report it to security@khorchapati.com and we will respond within 48 hours.

What we protect

  • Mobile numbers, email addresses, and password hashes
  • Transaction records, categories, and notes
  • Account balances and wallet information
  • Budget settings and savings goals
  • Family member information and access permissions

What we will never do

  • Sell your data to advertisers or data brokers
  • Share your financial data with third parties without your explicit consent
  • Access your bank or mobile money accounts
  • Store your passwords in plain text
  • Show you targeted ads based on your spending data

Two-factor authentication

We support PIN-based authentication for the mobile app as a second layer of protection beyond your password. Full two-factor authentication (TOTP/SMS) is on our roadmap.

Responsible disclosure

If you discover a security vulnerability in Khorchapati, please report it responsibly to security@khorchapati.com. Please do not publicly disclose the issue until we have had a chance to investigate and fix it. We aim to respond within 48 hours and will keep you updated on our progress.

We do not operate a formal bug bounty programme at this time, but we genuinely appreciate responsible disclosure and will thank you publicly (with your permission) for any valid report.