Back to Sprout

Legal

Security Overview

Security at Sprout is about clear, limited claims: protecting accounts, protecting transport, and keeping operational access narrow.

Last updated July 13, 2026

Account protection

Sprout uses authenticated accounts and standard session controls so users can access only their own data. We keep security claims narrow and do not describe controls we have not verified and documented.

Protected transport

Traffic to Sprout is served over HTTPS. That helps protect data in transit between your device and the service.

Operational posture

We aim to keep operational access limited and use only the infrastructure and connected services required to run the product. Sprout is privacy-first, which means we prefer simpler system boundaries over broad data collection.

Connected features

Features like CSV import, WhatsApp capture, Siri shortcuts, and API tokens expand what Sprout can do. They also expand the surface area of the product, so we treat them as optional integrations and document them plainly rather than implying bank-grade sync or compliance programs that do not exist.

Reporting an issue

If you believe you found a security issue, please email support with as much detail as you can provide, including reproduction steps and the account email involved if relevant. Use the same support address for security reports in v1.

Contact

Security questions or responsible disclosure reports

Email support@sprout-money.ca from the address associated with your Sprout account when relevant so we can verify and respond faster.

Related