Figena security model
All sensitive fields are encrypted locally with keys stored in the Secure Enclave. We never see or store your raw credentials or unencrypted ledger data.
Sync uses CloudKit with record-level encryption. Each device has its own keypair; revoking a device removes its ability to decrypt future data.
Biometric lock and session timeouts protect against shoulder surfing. You can require Face ID before opening sensitive screens like account numbers.