FEODIS

Security

You Are About to Give Us Your Social Security Number.

It is a fair thing to hesitate over, and most of this industry answers it with a padlock icon and the words “bank-level security,” which mean nothing. Here is what actually happens to it — six mechanisms, each one a thing the code does rather than a thing we intend.

  1. It Is Asked For Once, and Only After You Have Paid

    Nothing on this site asks for a Social Security number before checkout, and checkout itself never sees one — payment is handled off-site by Stripe, and Feodis does not receive or store your card number either.

    After payment you are asked for your legal name, the address already on your credit file, your date of birth and your Social Security number. That is the whole of it, and it is asked once. A credit bureau matches a new account to an existing file on those four things; without them an account has nobody to belong to.

  2. It Is Encrypted With a Key the Database Does Not Have

    The number is encrypted with AES-256-GCM before it is written down. The key is held in the application environment, never in the database and never in the repository — so a stolen copy of the database is not enough to read it. Someone would need the running environment as well, and the two are compromised by different mistakes.

    GCM rather than a cipher without authentication, because the tag makes tampering fail loudly. An attacker who could write to the row cannot flip bits in the stored value and have it quietly decrypt to something else that then gets furnished to a bureau; a tampered value throws instead. Every encryption uses a fresh random initialisation vector, stored alongside the ciphertext.

    If the key is not configured, the code refuses to handle the data at all rather than falling back to a default. A shared default key across deployments would make the encryption decoration.

  3. The Monthly Reporting Batch Does Not Contain It

    Reporting runs as a batch once a month. The record built for each member is assembled complete and then has the Social Security number removed before anything is stored — so the stored batch is not a second, plainer copy of every member's number sitting somewhere easier to reach than the encrypted column.

    It is decrypted in memory only at the moment of submission, and not kept afterwards.

  4. Reaching It Leaves a Record

    There is one export inside the back office that does contain Social Security numbers, because a bureau record is matched on one. It is restricted to administrators, it refuses to run on a batch that has not been reviewed and approved, and it is sent with cache headers that stop any proxy or browser keeping a copy.

    An audit row is written before the file is produced, not after — so a download that fails halfway through has still been recorded. There is no way to take that file without leaving evidence that it was taken.

  5. There Is No Password to Steal

    Signing in is a link emailed to the address you paid with. It works once and lasts fifteen minutes. Feodis stores no password, so there is no password database to breach, nothing to reuse from somewhere else you have been breached, and nothing for you to remember.

    The session itself is a signed, httpOnly, Secure cookie with SameSite protection, which means it cannot be read by scripts in the page and is not sent along by another site trying to act as you.

  6. The Site Loads No Third-Party Scripts

    Every page you have viewed on feodis.co loaded code from feodis.co and nowhere else. No advertising pixels, no session recorders, no chat widgets, no tag manager, no external fonts. Nothing on this site is watching you on behalf of someone who is not Feodis.

    That is enforced rather than intended: a Content Security Policy served with every page refuses to execute code from any other origin, refuses to let the site be framed by anyone, and refuses to let its forms post anywhere else. You do not have to take this one on trust — open your browser's network tab on any page here and read the list.

And What We Are Not Going to Claim

Feodis holds no security certification. There is no SOC 2 report, no ISO 27001, no completed third-party penetration test, and no compliance badge we could put at the bottom of this page. Plenty of sites in this category display something that looks like one. We would rather tell you there is nothing to display.

Feodis is also not a bank, and the phrase “bank-level security” appears nowhere on this site because it describes nothing measurable.

What is above is the whole of it. If any of it stops being true, this page is the first thing that should change.

Questions This Page Does Not Answer

What you are buying, what it costs, how long it takes to appear and how cancelling works are all on the FAQ. What we collect and why, in the formal sense, is in the privacy policy.

See the plans — from $7.99/month

No credit check · cancel any time, no fee