froider.
SECURITY & TRUST

Designed for deliberate control.

Protection requests should be easy to understand, difficult to abuse, and possible to audit.

01

Credentials stay separate

Froider never asks for a bank password. Demo connections use fictional authorization references only.

02

Verified requests

Password hashes use Argon2. Sessions use HttpOnly cookies. Emergency requests require recent verification and an explicit confirmation.

03

Traceable execution

Idempotent requests, a durable dispatch queue, timestamped events, and signed webhook validation make response paths inspectable.

04

Clear pilot boundaries

Simulated identity is not production MFA. Independent penetration testing, bank agreements, privacy assessment, and approved identity providers remain launch requirements.