SECURITY INFORMATION
Our regulated partners
Mary & Pip is not a broker-dealer. Your investment accounts are opened, held, and custodied by Alpaca Securities LLC, a member of FINRA and SIPC. SIPC protects the securities in your brokerage account up to $500,000, including $250,000 for cash.
Bank connections are powered by Plaid, the same technology used by Venmo, Robinhood, and hundreds of other financial apps. Plaid is a member of the Aspen Institute’s Financial Security Program and adheres to industry-standard encryption and security practices.
How we protect your data
Encryption in transit. Every connection between your device and our servers uses TLS 1.2 or 1.3 with FIPS-compliant cipher suites. Insecure HTTP requests are automatically redirected to HTTPS.
Encryption at rest. Our production database, Amazon Aurora PostgreSQL, is encrypted at rest, and connections to it are required to use SSL. Sensitive credentials—including the tokens used to sync bank data through Plaid—are additionally encrypted at the application layer using AES-256-GCM before being written to the database.
What we don’t store. We never store your full bank account number or your Social Security number. Identity verification is handled directly by Plaid and Alpaca, who are regulated to collect that information for account opening. We also don’t process or store credit or debit card numbers.
How we protect your account
Authentication. Sign-in is powered by Clerk, a specialized identity platform. Every API request from the app is authenticated with a short-lived, cryptographically verified token.
Isolation. Every request to our servers is scoped to your user identity, and our database queries enforce that scoping at the code level. One user’s data cannot be accessed from another user’s session.
Admin access. Internal staff who access administrative tools sign in with Google Workspace single sign-on restricted to a small allowlist of @maryandpip.com addresses. Every administrative action is written to an audit log: who, when, what, and from what IP.
How our infrastructure is built
Mary & Pip runs on Amazon Web Services (AWS). Our production environment includes:
Application servers run in private VPC subnets with no direct internet exposure.
The database is unreachable from the public internet—only our application servers can talk to it.
A web application firewall blocks common attack patterns, malicious bots, and abuse-rate patterns; least-privilege roles keep each service to the permissions it strictly needs.
Secrets are stored in AWS Secrets Manager, never source code. Multi-AZ redundancy, an Aurora reader replica, daily backups with 30-day retention, and deletion protection support continuity.
How we detect, respond, and stay current
Application errors and performance issues are captured in Sentry with sensitive fields automatically redacted. Server logs stream to AWS CloudWatch with PII redacted at the logger, administrative actions are kept in a permanent audit trail, and our production database is monitored with enhanced RDS monitoring and Performance Insights.
Automated dependency scanning runs weekly across our backend and mobile app. Vulnerability audits run on every pull request and production push, blocking high-severity findings. Our code is written in TypeScript with strict type checking, and every change is reviewed before it ships.
Our subprocessors
We rely on the following trusted vendors to help operate Mary & Pip. Each is bound by its own security and privacy commitments.
Amazon Web Services — Hosting, database, storage, and networking
Alpaca Securities LLC
Brokerage services (FINRA/SIPC member)
Plaid
Bank account connections and identity verification
Clerk
User authentication
Sentry
Error monitoring
Postmark
Transactional email
Expo
Mobile app distribution and push notifications
Google Workspace — Internal staff email and single sign-on
Reporting a security issue
If you believe you’ve found a security vulnerability in Mary & Pip, please email us at security@maryandpip.com. We take every report seriously and will acknowledge receipt within two business days. Please give us a reasonable window to investigate and address the issue before disclosing it publicly.
Last updated: July 28, 2026