Security
Security Center
Effective May 27, 2026
How SplitEase protects your account, your groups, and every expense and message inside them.
1.Encryption
Data is encrypted in transit using TLS between your device and SplitEase's servers.
Sensitive account and expense data is encrypted at rest, and access to production data stores is restricted to systems and personnel that need it to operate the service.
2.Access control
Internal access to user data is limited to authenticated staff on a need-to-know basis, and access is logged.
Your account is protected by authenticated sessions, and you can review and revoke active sessions from account settings.
3.Infrastructure and monitoring
SplitEase runs on reputable cloud infrastructure providers with their own physical and network security controls.
We monitor core services for abnormal activity and errors so issues can be caught and addressed quickly.
4.Compliance posture
Our security practices are shaped around widely recognized frameworks, including GDPR, SOC 2, ISO/IEC 27001, ISO/IEC 22301, and PCI DSS principles, reflected in the trust badges shown across the site.
This reflects the standards we design towards; it is not a claim of formal per-framework certification unless stated otherwise in writing.
5.Incident response
If a security incident affects your account or data, we will investigate promptly and notify affected users where required by law or where the impact is material.
We continuously review and patch dependencies and infrastructure to reduce exposure to known vulnerabilities.
6.Responsible disclosure
If you believe you've found a security vulnerability in SplitEase, please report it to our support team with enough detail to reproduce the issue.
Please avoid accessing, modifying, or deleting other users' data while testing, and give us a reasonable time to investigate and respond before disclosing publicly.
Found a vulnerability, or want details on a specific control? We want to hear from you.
Contact supportRelated policies