Trust

Security

FinalOut handles sensitive planning data for service members and veterans. Here is what we do to protect it, and what we deliberately do not collect.

Technical safeguards

  • TLS encryption in transit for all traffic
  • Encryption at rest for all databases
  • Field-level encryption for sensitive VA condition labels in the application layer
  • Audit logging on every read/write of sensitive data
  • Rate limiting on all API endpoints
  • Third-party authentication (Clerk) with no plaintext passwords stored by FinalOut
  • Error monitoring with request bodies scrubbed before transmission to our monitoring provider

What we never do

  • Ask for your Social Security number, full date of birth, or dependent names
  • Accept DD214, medical record, or service treatment record uploads
  • Store raw PHI or ePHI
  • Sell your data or use your inputs for ad targeting

The platform is not currently certified to store PII, PHI, ePHI, or CUI beyond the limited planning fields described in our Privacy Policy. Do not enter medical record numbers, diagnostic codes, or full medical narratives.

Data deletion

You can permanently delete your account and all associated data at any time from Account Settings. Deletion is immediate and cannot be undone.

Report a security concern

If you believe you've found a security vulnerability, email security@finalout.app with details and steps to reproduce. We investigate all reports and will follow up directly.