Credentials stay separate
Froider never asks for a bank password. Demo connections use fictional authorization references only.
froider.Protection requests should be easy to understand, difficult to abuse, and possible to audit.
Froider never asks for a bank password. Demo connections use fictional authorization references only.
Password hashes use Argon2. Sessions use HttpOnly cookies. Emergency requests require recent verification and an explicit confirmation.
Idempotent requests, a durable dispatch queue, timestamped events, and signed webhook validation make response paths inspectable.
Simulated identity is not production MFA. Independent penetration testing, bank agreements, privacy assessment, and approved identity providers remain launch requirements.