Trust
Security
FinalOut handles sensitive planning data for service members and veterans. Here is what we do to protect it, and what we deliberately do not collect.
Technical safeguards
- TLS encryption in transit for all traffic
- Encryption at rest for all databases
- Field-level encryption for sensitive VA condition labels in the application layer
- Audit logging on every read/write of sensitive data
- Rate limiting on all API endpoints
- Third-party authentication (Clerk) with no plaintext passwords stored by FinalOut
- Error monitoring with request bodies scrubbed before transmission to our monitoring provider
What we never do
- Ask for your Social Security number, full date of birth, or dependent names
- Accept DD214, medical record, or service treatment record uploads
- Store raw PHI or ePHI
- Sell your data or use your inputs for ad targeting
The platform is not currently certified to store PII, PHI, ePHI, or CUI beyond the limited planning fields described in our Privacy Policy. Do not enter medical record numbers, diagnostic codes, or full medical narratives.
Data deletion
You can permanently delete your account and all associated data at any time from Account Settings. Deletion is immediate and cannot be undone.
Report a security concern
If you believe you've found a security vulnerability, email security@finalout.app with details and steps to reproduce. We investigate all reports and will follow up directly.