Security

Last updated on September 16, 2026.

Juno Wealth is used by financial planners and advisors, which means it handles some of the most sensitive material its users hold. We take reports of security problems seriously and we would rather hear about a problem from you than from a customer.

Reporting a vulnerability

Email security@thenevercompany.ai. You do not need an existing relationship with us to report something, and you will not be penalised for reporting in good faith.

Where you can, please include:

  • What the issue is, and what an attacker could do with it
  • The steps needed to reproduce it
  • The URL or the part of Juno Wealth affected
  • How you would like to be credited, if you would like to be credited at all

What we commit to

  • We acknowledge your report within two business days.
  • We tell you whether we have reproduced the issue, and give you an honest assessment of severity.
  • We keep you updated while we work on a fix, rather than going quiet.
  • We tell you when it is fixed, and credit you publicly if you want that.

If an issue affects customer data, we notify affected customers promptly and factually — including what we know, what we do not yet know, and what we are doing about it. Our customers carry their own regulatory notification duties, so vagueness on our part creates a problem for them, not only for us.

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider your research authorised, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you. Good faith means: report promptly, test only with accounts you own, do not access or modify data belonging to anyone else, do not degrade the service for other users, and give us reasonable time to fix the issue before disclosing it publicly.

If legal action is initiated by a third party against you for activity conducted in accordance with this policy, we will make this authorisation known.

Scope

In scope:

  • The Juno Wealth web application at app.junowealth.ai
  • The Juno-operated services behind it, including our AI service
  • This website

Out of scope:

  • Denial-of-service and volumetric testing
  • Social engineering of our people, customers, or vendors
  • Physical attacks
  • Reports from automated scanners without a demonstrated, exploitable impact
  • Vulnerabilities in third-party services we use — please report those to the third party, though we would still like to know

How Juno Wealth is built

Some architectural facts that are usually the next question after "how do I report something":

  • Your data is stored on Google Cloud, including Google's Firebase platform, and is encrypted in transit and at rest. Access is restricted to the systems that run Juno Wealth and to authorised members of our team who need it.
  • AI requests are not retained. Our servers pass each request to a model provider and do not store, cache or log its content. Models are hosted only by zero-data-retention providers, and nothing you send is used to train them.
  • AI provider credentials stay on our servers. They are never sent to your browser.

Our Privacy Policy describes data handling in full. Juno Wealth is not SOC 2 certified. If you are performing vendor diligence and need detail beyond this page, write to security@thenevercompany.ai.