Security

Built so we can't touch your money.

The safest way to protect money is not to hold it. Pennypact keeps the record and prepares payment requests; the money moves between people on services they already use. What's left to protect is the record and your details, and that's what this page is about.

What we never do

Six things that never change

There is no bank credential to steal, no balance to drain and no key to lose, because none of them exist here.

  • Never ask for a bank login or an open-banking permission.
  • Never hold, pool, route or move your money.
  • Never take custody of a wallet or a key.
  • Never issue a coin or a token.
  • Never sell, broker or advertise against your spending.
  • Never let a link show more than the one bill it was made for.

What's checkable

A record you can check without trusting us

Every accepted record — an expense, a change to the split rules, a confirmed payment — gets a privacy-blinded fingerprint. We publish those to Base in batches we pay for and checkpoint each day's batches once on Ethereum.

Nothing private goes on-chain

No names, amounts, currencies, descriptions, contacts or receipts. The fingerprint is blinded with a random value only the pact holds, so the public record reveals nothing without your private copy.

An independent check

Download a record from any pact you're in and check it on your own device with the CommitMatch verifier at commitmatch.com, with the network off if you like. It shows the record existed by that moment and hasn't changed. It does not show the expense was fair or the money moved.

History is never rewritten

Corrections are new versions approved by the group; removals are marked, not erased. Each pact's records link to the one before, so a missing record would show as a gap.

Your details

How we protect what we do hold

The record itself, your contact details and your receipts live with us. Here is how they're kept.

  • Encrypted at rest. Contact details, expense descriptions, receipt names and payment details are encrypted with keys we manage separately from the data. Lookups use a keyed hash, not the value.
  • Links are handled like passwords. A link's secret is hashed the moment it arrives and never written to a log. Links that do something irreversible work once.
  • Every action is attributed. Each change records who made it and when. Guests see only their own rows; a link holder can do only its one job.
  • Sessions you control. Sign out everywhere from your account page. Deleting your account starts a 15-day window, after which everything of yours is removed, receipts included.
  • Boring infrastructure on purpose. One database, one object store, one queue, strict separation between production and testing. Logs carry opaque ids only.

What isn't live yet

Pennypact is pre-launch, so be clear-eyed about this page: publishing to Base and Ethereum runs against test networks today, the verifier at commitmatch.com accepts test records until the production contracts are audited, and no country is open. Everything above describes what launches, not what you can use this afternoon. When that changes, this paragraph will.

Found something?

Email hello@pennypact.com with "Security" in the subject. We read every report, answer within a few days, and won't take action against anyone who reports in good faith.

Reviewed September 5, 2026.