securo-finance/securoPublic

Open-source personal finance manager. Self-hosted, privacy-first.

AI summary: An open-source, self-hosted personal finance manager designed for complete data sovereignty.

Stars
3.9K
+45 today
Forks
512
Watchers
15
Open issues
196
Open PRs
46
Contributors
~91
Commits
513
Branches
176

PythonAGPL-3.0Created Mar 8, 2026Last push 2d agoLatest release v0.16.2+136 stars this week+933 this month

Quick answers

What is securo?
An open-source, self-hosted personal finance manager designed for complete data sovereignty.
What does securo do?
Securo is a privacy-focused personal finance and budgeting application designed to run entirely on user-controlled infrastructure. By keeping the platform self-hosted, it prevents third-party corporations and advertisers from accessing or analyzing sensitive financial data. The platform aggregates bank account information, tracks spending habits, and visualizes overall financial health through a comprehensive dashboard. It is available via a simple installation script and is strictly licensed under the AGPL-3.0 to ensure transparency. Ultimately, it provides a secure alternative to popular cloud-based budgeting applications that monetize user data.
Who is securo for?
Securo is built for privacy advocates, home lab enthusiasts, and individuals demanding granular control over their personal finances. It appeals strongly to users who distrust commercial finance applications that monetize user data.
How do I get started with securo?
curl -fsSL https://usesecuro.com/install.sh | bash
How popular is securo on GitHub?
securo-finance/securo has 3,910 stars and 512 forks on GitHub, and gained 136 stars in the last 7 days.
What license does securo use?
securo-finance/securo is released under the AGPL-3.0 license.

Star history

since Aug 27, 2026
01K2K3KAug 2026Sep 2026Sep 2026Oct 2026
3.9K stars as of Oct 3, 2026. Measured daily since Aug 27, 2026; GitHub no longer exposes earlier star timestamps.

Contribution activity

commits per day, last 52 weeks
OctNovDecJanFebMarAprMayJunJulAugSepMonWedFri2025-10-04: 0 commits2025-10-05: 0 commits2025-10-06: 0 commits2025-10-07: 0 commits2025-10-08: 0 commits2025-10-09: 0 commits2025-10-10: 0 commits2025-10-11: 0 commits2025-10-12: 0 commits2025-10-13: 0 commits2025-10-14: 0 commits2025-10-15: 0 commits2025-10-16: 0 commits2025-10-17: 0 commits2025-10-18: 0 commits2025-10-19: 0 commits2025-10-20: 0 commits2025-10-21: 0 commits2025-10-22: 0 commits2025-10-23: 0 commits2025-10-24: 0 commits2025-10-25: 0 commits2025-10-26: 0 commits2025-10-27: 0 commits2025-10-28: 0 commits2025-10-29: 0 commits2025-10-30: 0 commits2025-10-31: 0 commits2025-11-01: 0 commits2025-11-02: 0 commits2025-11-03: 0 commits2025-11-04: 0 commits2025-11-05: 0 commits2025-11-06: 0 commits2025-11-07: 0 commits2025-11-09: 0 commits2025-11-10: 0 commits2025-11-11: 0 commits2025-11-12: 0 commits2025-11-13: 0 commits2025-11-14: 0 commits2025-11-15: 0 commits2025-11-16: 0 commits2025-11-17: 0 commits2025-11-18: 0 commits2025-11-19: 0 commits2025-11-20: 0 commits2025-11-21: 0 commits2025-11-22: 0 commits2025-11-23: 0 commits2025-11-24: 0 commits2025-11-25: 0 commits2025-11-26: 0 commits2025-11-27: 0 commits2025-11-28: 0 commits2025-11-29: 0 commits2025-11-30: 0 commits2025-12-01: 0 commits2025-12-02: 0 commits2025-12-03: 0 commits2025-12-04: 0 commits2025-12-05: 0 commits2025-12-06: 0 commits2025-12-07: 0 commits2025-12-08: 0 commits2025-12-09: 0 commits2025-12-10: 0 commits2025-12-11: 0 commits2025-12-12: 0 commits2025-12-13: 0 commits2025-12-14: 0 commits2025-12-15: 0 commits2025-12-16: 0 commits2025-12-17: 0 commits2025-12-18: 0 commits2025-12-19: 0 commits2025-12-20: 0 commits2025-12-21: 0 commits2025-12-22: 0 commits2025-12-23: 0 commits2025-12-24: 0 commits2025-12-25: 0 commits2025-12-26: 0 commits2025-12-27: 0 commits2025-12-28: 0 commits2025-12-29: 0 commits2025-12-30: 0 commits2025-12-31: 0 commits2026-01-01: 0 commits2026-01-02: 0 commits2026-01-03: 0 commits2026-01-04: 0 commits2026-01-05: 0 commits2026-01-06: 0 commits2026-01-07: 0 commits2026-01-08: 0 commits2026-01-09: 0 commits2026-01-10: 0 commits2026-01-11: 0 commits2026-01-12: 0 commits2026-01-13: 0 commits2026-01-14: 0 commits2026-01-15: 0 commits2026-01-16: 0 commits2026-01-17: 0 commits2026-01-18: 0 commits2026-01-19: 0 commits2026-01-20: 0 commits2026-01-21: 0 commits2026-01-22: 0 commits2026-01-23: 0 commits2026-01-24: 0 commits2026-01-25: 0 commits2026-01-26: 0 commits2026-01-27: 0 commits2026-01-28: 0 commits2026-01-29: 0 commits2026-01-30: 0 commits2026-01-31: 0 commits2026-02-01: 0 commits2026-02-02: 0 commits2026-02-03: 0 commits2026-02-04: 0 commits2026-02-05: 0 commits2026-02-06: 0 commits2026-02-07: 0 commits2026-02-08: 0 commits2026-02-09: 0 commits2026-02-10: 0 commits2026-02-11: 0 commits2026-02-12: 0 commits2026-02-13: 0 commits2026-02-14: 0 commits2026-02-15: 0 commits2026-02-16: 0 commits2026-02-17: 0 commits2026-02-18: 0 commits2026-02-19: 0 commits2026-02-20: 0 commits2026-02-21: 0 commits2026-02-22: 0 commits2026-02-23: 0 commits2026-02-24: 0 commits2026-02-25: 0 commits2026-02-26: 0 commits2026-02-27: 0 commits2026-02-28: 0 commits2026-03-01: 0 commits2026-03-02: 0 commits2026-03-03: 0 commits2026-03-04: 0 commits2026-03-05: 0 commits2026-03-06: 0 commits2026-03-07: 0 commits2026-03-08: 0 commits2026-03-09: 0 commits2026-03-10: 5 commits2026-03-11: 5 commits2026-03-12: 7 commits2026-03-13: 1 commit2026-03-14: 0 commits2026-03-15: 2 commits2026-03-16: 1 commit2026-03-17: 1 commit2026-03-18: 0 commits2026-03-19: 1 commit2026-03-20: 2 commits2026-03-21: 1 commit2026-03-22: 0 commits2026-03-23: 1 commit2026-03-24: 3 commits2026-03-25: 3 commits2026-03-26: 0 commits2026-03-27: 6 commits2026-03-28: 0 commits2026-03-29: 0 commits2026-03-30: 5 commits2026-03-31: 1 commit2026-04-01: 4 commits2026-04-02: 0 commits2026-04-03: 3 commits2026-04-04: 2 commits2026-04-05: 0 commits2026-04-06: 0 commits2026-04-07: 1 commit2026-04-08: 1 commit2026-04-09: 2 commits2026-04-10: 2 commits2026-04-11: 2 commits2026-04-12: 0 commits2026-04-13: 0 commits2026-04-14: 4 commits2026-04-15: 0 commits2026-04-16: 3 commits2026-04-17: 2 commits2026-04-18: 3 commits2026-04-19: 6 commits2026-04-20: 2 commits2026-04-21: 2 commits2026-04-22: 4 commits2026-04-23: 4 commits2026-04-24: 4 commits2026-04-25: 0 commits2026-04-26: 7 commits2026-04-27: 1 commit2026-04-28: 0 commits2026-04-29: 0 commits2026-04-30: 0 commits2026-05-01: 1 commit2026-05-02: 3 commits2026-05-03: 4 commits2026-05-04: 3 commits2026-05-05: 0 commits2026-05-06: 3 commits2026-05-07: 5 commits2026-05-08: 0 commits2026-05-09: 1 commit2026-05-10: 3 commits2026-05-11: 0 commits2026-05-12: 3 commits2026-05-13: 2 commits2026-05-14: 0 commits2026-05-15: 0 commits2026-05-16: 0 commits2026-05-17: 3 commits2026-05-18: 1 commit2026-05-19: 3 commits2026-05-20: 0 commits2026-05-21: 7 commits2026-05-22: 0 commits2026-05-23: 0 commits2026-05-24: 0 commits2026-05-25: 2 commits2026-05-26: 0 commits2026-05-27: 1 commit2026-05-28: 0 commits2026-05-29: 7 commits2026-05-30: 2 commits2026-05-31: 1 commit2026-06-01: 3 commits2026-06-02: 5 commits2026-06-03: 4 commits2026-06-04: 3 commits2026-06-05: 4 commits2026-06-06: 5 commits2026-06-07: 2 commits2026-06-08: 6 commits2026-06-09: 3 commits2026-06-10: 5 commits2026-06-11: 6 commits2026-06-12: 0 commits2026-06-13: 3 commits2026-06-14: 4 commits2026-06-15: 3 commits2026-06-16: 1 commit2026-06-17: 2 commits2026-06-18: 2 commits2026-06-19: 3 commits2026-06-20: 0 commits2026-06-21: 0 commits2026-06-22: 0 commits2026-06-23: 2 commits2026-06-24: 1 commit2026-06-25: 1 commit2026-06-26: 0 commits2026-06-27: 0 commits2026-06-28: 0 commits2026-06-29: 2 commits2026-06-30: 8 commits2026-07-01: 1 commit2026-07-02: 3 commits2026-07-03: 0 commits2026-07-04: 0 commits2026-07-05: 0 commits2026-07-06: 8 commits2026-07-07: 3 commits2026-07-08: 0 commits2026-07-09: 2 commits2026-07-10: 1 commit2026-07-11: 0 commits2026-07-12: 0 commits2026-07-13: 4 commits2026-07-14: 3 commits2026-07-15: 0 commits2026-07-16: 0 commits2026-07-17: 0 commits2026-07-18: 0 commits2026-07-19: 0 commits2026-07-20: 0 commits2026-07-21: 8 commits2026-07-22: 0 commits2026-07-23: 0 commits2026-07-24: 0 commits2026-07-25: 4 commits2026-07-26: 0 commits2026-07-27: 0 commits2026-07-28: 0 commits2026-07-29: 4 commits2026-07-30: 7 commits2026-07-31: 0 commits2026-08-01: 0 commits2026-08-02: 0 commits2026-08-03: 10 commits2026-08-04: 3 commits2026-08-05: 8 commits2026-08-06: 2 commits2026-08-07: 1 commit2026-08-08: 0 commits2026-08-09: 0 commits2026-08-10: 21 commits2026-08-11: 0 commits2026-08-12: 3 commits2026-08-13: 2 commits2026-08-14: 2 commits2026-08-15: 0 commits2026-08-16: 3 commits2026-08-17: 3 commits2026-08-18: 2 commits2026-08-19: 6 commits2026-08-20: 8 commits2026-08-21: 1 commit2026-08-22: 3 commits2026-08-23: 1 commit2026-08-24: 5 commits2026-08-25: 6 commits2026-08-26: 5 commits2026-08-27: 7 commits2026-08-28: 0 commits2026-08-29: 0 commits2026-08-30: 0 commits2026-08-31: 15 commits2026-09-01: 4 commits2026-09-02: 7 commits2026-09-03: 8 commits2026-09-04: 1 commit2026-09-05: 7 commits2026-09-06: 3 commits2026-09-07: 1 commit2026-09-08: 8 commits2026-09-09: 0 commits2026-09-10: 0 commits2026-09-11: 0 commits2026-09-12: 0 commits2026-09-13: 0 commits2026-09-14: 0 commits2026-09-15: 0 commits2026-09-16: 22 commits2026-09-17: 2 commits2026-09-18: 4 commits2026-09-19: 0 commits2026-09-20: 0 commits2026-09-21: 6 commits2026-09-22: 8 commits2026-09-23: 19 commits2026-09-24: 5 commits2026-09-25: 2 commits2026-09-26: 0 commits2026-09-27: 0 commits2026-09-28: 0 commits2026-09-29: 0 commits2026-09-30: 0 commits2026-10-01: 0 commits2026-10-02: 0 commits2026-10-03: 0 commits
509 commits in the last yearLessMore

Signals and awards

derived from tracked data
  • Very active

    509 commits in 52 weeks

  • Well documented

    High community health score

  • Continuous integration

    Automated checks passing

  • Repeat trending

    4 trending appearances

What securo does

Securo is a privacy-focused personal finance and budgeting application designed to run entirely on user-controlled infrastructure. By keeping the platform self-hosted, it prevents third-party corporations and advertisers from accessing or analyzing sensitive financial data. The platform aggregates bank account information, tracks spending habits, and visualizes overall financial health through a comprehensive dashboard. It is available via a simple installation script and is strictly licensed under the AGPL-3.0 to ensure transparency. Ultimately, it provides a secure alternative to popular cloud-based budgeting applications that monetize user data.

Securo is built for privacy advocates, home lab enthusiasts, and individuals demanding granular control over their personal finances. It appeals strongly to users who distrust commercial finance applications that monetize user data.

  • Self hosted infrastructure: Runs entirely on your own servers or home lab to guarantee complete data sovereignty.
  • Comprehensive dashboard: Visualizes spending habits, account balances, and financial trends in a clear interface.
  • Privacy focused architecture: Prevents the transmission of personal financial data to any third-party analytics engines.
  • Open source transparency: Licensed under AGPL 3.0, ensuring the codebase remains transparent and auditable.
  • Easy deployment: Offers a simple curl-to-bash installation script for quick setup on compatible systems.

Where teams use it

Managing personal budgets

Users track their monthly expenses and income streams securely without relying on commercial SaaS products.

Consolidating financial data

Individuals bring multiple account histories into a single unified view hosted safely on a home server.

Enhancing data privacy

Privacy advocates ensure their sensitive financial records remain strictly confidential and off corporate servers.

Analyzing spending habits

Users categorize and review historical transactions using built in tools to make better financial decisions.

Getting started: curl -fsSL https://usesecuro.com/install.sh | bash

README

main branch

Securo logo

Securo

CI Coverage Downloads
Artifact Hub License: AGPL-3.0 Join our Discord
Website · Demo · Roadmap · Docs · Discord · Talk to the maintainer

Finance apps want your data. This one doesn't.

We believe personal finance should actually be personal. No corporation should sit between you and your financial data. Securo is an open-source finance manager that runs on your own infrastructure, giving you full visibility into your accounts, spending, and habits, without surrendering a single byte to third parties. Take back control.

Quick Start

Linux & macOS (uses Docker or Podman; installs Docker if neither is present):

curl -fsSL https://usesecuro.com/install.sh | bash

Windows: Install Docker Desktop, then:

git clone https://github.com/securo-finance/securo.git && cd securo
docker compose up --build

Open http://localhost:3000 and create an account. That's it.

Securo dashboard

Features

  • Multi-account management with running balances
  • Transaction management with search, filters, and CSV export
  • File import (OFX, QIF, CAMT, CSV)
  • Auto-categorization rules engine
  • Recurring transactions and budgets
  • Goals and savings targets with progress tracking
  • Asset management with valuation tracking and growth rules
  • Reports: Net Worth and Income vs Expenses with category sparklines
  • Bank sync via providers (Pluggy for Brazilian banks, Enable Banking for ~2500 European PSD2 banks, SimpleFIN for US and international banks, extensible)
  • Multi-currency support with automatic FX conversion
  • Multi-user support with admin panel and registration controls
  • Two-factor authentication (TOTP) with brute-force protection
  • OIDC login support for Authentik, Pocket ID, and other standard providers
  • AI Agents (optional): self-hosted LLM chat with tool-use over your data, plus a per-agent RAG knowledge base

Bank Sync (Optional)

Add credentials for any of the supported providers to .env, then restart with docker compose up. Configure one or both — each provider auto-registers when its credentials are present.

Pluggy — Brazilian banks

Sign up at pluggy.ai and add:

PLUGGY_CLIENT_ID=your-client-id
PLUGGY_CLIENT_SECRET=your-client-secret

Enable Banking — European banks (PSD2)

Sign up at enablebanking.com, create a Production application, and download its PEM private key. Save the PEM to ./secrets/ (gitignored), then add:

ENABLE_BANKING_APP_ID=your-application-id
ENABLE_BANKING_PRIVATE_KEY_FILE=/app/secrets/your-key.pem
ENABLE_BANKING_OAUTH_REDIRECT_URI=https://your-host/oauth/callback

The redirect URI must match exactly one of the Allowed Redirect URLs in your EB application. Production EB requires HTTPS — for local development, expose your frontend via a tunnel (ngrok, cloudflared) or use the EB sandbox.

Free tier — restricted mode. Enable Banking's free plan requires you to pre-link the accounts you want to import inside the EB portal before connecting from Securo. If you skip that step, the connection returns no accounts and Securo will surface a banner with a link to the portal.

SimpleFIN — US and international banks

SimpleFIN is a read-only open protocol. No API key needed — each connection brings its own credentials via a single-use Setup Token from the SimpleFIN Bridge. Just enable the feature:

SIMPLEFIN_ENABLED=true
SIMPLEFIN_API_URL=https://beta-bridge.simplefin.org   # sandbox; use bridge.simplefin.org for real banks

Then in Securo: Accounts → Connect Bank → SimpleFIN, and paste the token. The developer page gives out free demo tokens if you want to try it without a real bank.

OIDC Login (Optional)

Securo can delegate login to any standard OIDC provider, including Authentik and Pocket ID. Create a confidential/web application in your provider and register this redirect URI:

https://your-securo-host/api/auth/oidc/callback

Then add the provider settings to .env and restart:

OIDC_ENABLED=true
OIDC_PROVIDER_NAME=Pocket ID
OIDC_DISCOVERY_URL=https://id.example.com/.well-known/openid-configuration
OIDC_CLIENT_ID=securo
OIDC_CLIENT_SECRET=your-client-secret
# Optional; defaults to ${FRONTEND_URL}/api/auth/oidc/callback
OIDC_REDIRECT_URI=https://your-securo-host/api/auth/oidc/callback

To require SSO-only access after OIDC is configured, set LOCAL_AUTH_ENABLED=false. Securo will start in this mode only when OIDC_ENABLED=true, OIDC_CLIENT_ID, and OIDC_DISCOVERY_URL are all configured; otherwise startup fails with a validation error instead of leaving the instance with no usable login method. The login page shows an explicit configuration error if the server reports that neither local auth nor OIDC is available. If only the optional OIDC-config request fails, the client keeps local controls available with a warning; the backend remains authoritative and still rejects them in OIDC-only mode.

With local auth disabled, Securo rejects password and passkey login, public registration, first-admin password setup, admin or workspace-invite creation of password-backed users, forgot/reset-password requests, password updates, new passkey registration or verification, and new TOTP setup or enablement. Local credential controls are hidden from login, account, setup, registration, and admin user-management screens. Existing users, password hashes, active sessions, passkeys, and TOTP configuration are not deleted; existing passkeys and TOTP can still be removed as cleanup paths. OIDC user provisioning and existing-account linking remain controlled separately by OIDC_AUTO_REGISTER and OIDC_EXISTING_USER_LINK_MODE.

On a fresh OIDC-only instance, the first account must be provisioned through OIDC. Keep OIDC_AUTO_REGISTER=true, enable OIDC_SYNC_ROLES=true, and include one of the values from OIDC_ADMIN_ROLES in that identity's configured roles claim so the first login becomes a Securo administrator. Do not disable OIDC auto-registration before at least one matching account exists.

New OIDC users are auto-provisioned by default (OIDC_AUTO_REGISTER=true) using verified email addresses. Set OIDC_AUTO_REGISTER=false to allow only existing Securo users whose email matches the provider claim.

Linking existing accounts

An account that already exists in Securo (created with a password) is never linked to an OIDC identity automatically, so the first SSO login of an existing user is rejected by default. OIDC_EXISTING_USER_LINK_MODE controls that:

OIDC_EXISTING_USER_LINK_MODE=disabled
Value Behavior
disabled (default) Never link. Existing accounts must keep using password login.
verified_email Link the existing account when the provider sends email_verified=true for the same email.
email Link on a matching email alone, even without email_verified.

Use verified_email to move existing users to SSO without recreating their accounts and data. Only pick email if you trust your provider to own every address it asserts, since anyone able to set an email there could claim the matching Securo account. An OIDC identity already linked to another account is always rejected, in every mode.

Optional OIDC role sync

Securo can also synchronize provider roles/groups into its built-in permissions when OIDC_SYNC_ROLES=true. The default claim is groups, which works well with Authentik group mappings and Pocket ID role/group assignments.

OIDC_SYNC_ROLES=true
OIDC_ROLES_CLAIM=groups
OIDC_ADMIN_ROLES=securo-admins
OIDC_WORKSPACE_ROLE_MAP={"securo-owners":"owner","securo-editors":"editor","securo-viewers":"viewer"}

OIDC_ADMIN_ROLES grants or revokes Securo admin (is_superuser) on each OIDC login. OIDC_WORKSPACE_ROLE_MAP maps provider roles/groups to the user's Personal workspace role (owner, editor, or viewer); if multiple mapped roles are present, Securo applies the highest permission. Leave OIDC_SYNC_ROLES=false to keep all Securo roles managed locally.

Passkeys (Optional)

Sign in with Touch ID, Face ID, Windows Hello, or a security key. Passkeys are on by default and need no configuration: they follow whatever address you open Securo on.

Two rules come from the WebAuthn standard itself, and no setting can work around them:

  • An IP address is never valid. http://192.168.1.10:3000 cannot register passkeys.
  • Plain HTTP is never valid, except on localhost.

So use passkeys on http://localhost:3000, or put Securo on a domain behind an HTTPS reverse proxy. When serving from a domain, point FRONTEND_URL at it (this also covers CORS and OAuth callbacks):

FRONTEND_URL=https://securo.example.com

To pin passkeys to one domain, set WEBAUTHN_RP_ID (use the parent domain if you reach Securo on several subdomains). Otherwise Securo follows the browser, and requests from an unusable address get an explanation in the UI instead of a silent failure.

Exchange Rates (Optional)

For automatic currency conversion, add a free Open Exchange Rates key to .env:

OPENEXCHANGERATES_APP_ID=your-app-id

Rates are fetched on-demand when foreign-currency transactions are created. Without a key, cross-currency amounts default to a 1:1 fallback rate with a visual warning.

Timezone

Balances, budgets, due dates and recurring transactions turn over at midnight in the application timezone. Set it once in Admin Settings → Date and time; a workspace that keeps its books somewhere else can pick its own timezone in Workspace settings. Without a saved value the application follows TZ from the environment, then the host timezone, then UTC, so an existing installation keeps behaving as before until someone changes it.

AI Agents (Optional)

Self-hosted AI assistants over your Securo data — multi-provider (OpenAI, Anthropic, Ollama, OpenAI-compatible), tool-use via MCP, per-agent RAG knowledge base, ⌘J global chat panel.

Add to .env:

AGENTS_ENABLED=true
COMPOSE_PROFILES=agents

Then docker compose up -d. Settings → AI Agents to add a provider connection. Off by default; zero cost when off.

Without Docker

COMPOSE_PROFILES=agents only tells Docker Compose to start the extra mcp-server container, so on a bare-metal or LXC install set AGENTS_ENABLED=true alone. The built-in MCP server is a plain uvicorn app in the same virtualenv; run it next to the API and point the backend at it:

# alongside the API/worker/beat processes
uvicorn mcp_server.main:app --host 127.0.0.1 --port 8765
AGENTS_ENABLED=true
AGENTS_BUILTIN_MCP_URL=http://127.0.0.1:8765/mcp

Without that server the agents still chat, but they have no tools and cannot read your data. The backend log says which MCP server it failed to reach.

Tech Stack

Layer Stack
Backend FastAPI, SQLAlchemy, Alembic, Celery
Frontend React, TypeScript, Vite, Tailwind CSS
Database PostgreSQL
Queue Redis + Celery

AI-Assisted Development

Parts of this codebase were built with help of AI. All code is human-reviewed and no data leaves your environment.

Contributing with AI is welcome. We review the author, not the tool: whatever wrote the diff, you own its quality, its fit with where Securo is going, and everything that happens after it merges. See Using AI.

Development

# Run backend tests (from backend/, needs Python 3.11+; same as CI)
cd backend
pip install -e ".[dev]"   # first time only — installs pytest and dev deps
pytest

# Rebuild after dependency changes
docker compose up --build

If you've mise installed, you can install backend/frontend directly with it:

# Install the Python version specified in .python-version,
# and create a project virtual environment using that Python.
# Install all tools and dependencies (include Python with dedicated venv)
mise //...:install

# Install only backend tools/deps
mise backend:install

# Run backend tests
mise backend:test

# Install frontend dependencies
mise frontend:install

# Run frontend linting
mise frontend:lint

# Run frontend build
mise frontend:build

Contributing

See CONTRIBUTING.md for guidelines.

Not sure where to start, or want to talk something through first? Book 15 minutes — no agenda needed. Something broken, an idea, or just what you think of Securo, all welcome.

License

This project is licensed under the GNU Affero General Public License v3.0.

This means you can freely use, modify, and distribute this software, but any modifications — including when used as a network service (SaaS) — must also be released under the AGPL-3.0.

View on GitHub

Recent activity

commits and pull requests

Recent open issues

view all

Releases and announcements

83 total
  1. v0.16.2v0.16.2Sep 25, 2026

    In this release invoicing learned the three shapes money actually takes: an agreement that bills every period, a total split into instalments the client agreed to, and debt closed by a deduction rather than a payment. There is a catalog to pick lines from instead of typing them, and a workspace can keep its books in a timezone of its own. On the fixes side, CSV import reads thousands separators, an OFX file whose bank reuses one FITID keeps every row, editing a tracked holding no longer wipes its cost basis, and a user with reconciliation history can be deleted. ## Features - **Recurring invoices.** An agreement with a client emits one invoice per period, for a retainer, a plan or anything subscription-shaped, with the price kept as dated terms: a change applies from the first period starting on or after its date, and nothing is prorated. The page shows what each agreement bills per month, what is still to come, and every period written so far; one written by hand can be linked to the period it belongs to (#988) - **Instalments.** "3x", or "half upfront, half on delivery": the schedule the client agreed to, as rows that add up to the total. The invoice's due date becomes the last

  2. v0.16.1v0.16.1Sep 22, 2026

    In this release we put transfer pairing on the Rules page, where its thresholds are rows you can read, reorder and switch off like every other matching rule, and a pair that two candidates fit equally well is asked about instead of guessed. Reports take a custom date range, the desktop sidebar collapses, and four currencies joined the list. On the fixes side, bank sync got a round of correctness work across SimpleFIN and imports, a Pluggy consolidated credit line stops being counted once per card, a long agent conversation answers the newest message rather than the oldest, and receipts upload over plain HTTP again. ## Features - **Transfer pairing moved onto the Rules page.** The window, the signals and the decision to link rather than ask were 142 lines of constants nobody could see; they are now a card of rules next to the invoice and recurring sets, to reorder, edit, switch off, export or import. A pair is linked only when each leg is the other's single best answer, so two same-amount transfers leaving one account on the same day reach the queue instead of pairing at random, and a card purchase leaves the candidate pool before any rule runs. Closes #973 (#985) - **Reports take

  3. v0.16.0v0.16.0Sep 17, 2026

    <img width="1567" height="409" alt="reconciliation-queue" src="https://github.com/user-attachments/assets/9723f68b-0a97-42ce-908b-cf67e807db25" /> In this release we added payment matching: money that lands in an account binds itself to the invoice it settles, what it cannot decide alone goes to a queue, and the rules behind it are a list you can read, reorder and rewrite. Indian workspaces get an April to March financial year, seven currencies joined the list, and rules gained a full editor when adding a transaction to one and a way to be managed through MCP. On the fixes side, editing a recurring schedule moves its next occurrence, synced card installments inherit the category you gave the first one, a credit card bill no longer shrinks when a charge is tagged as a transfer, and the payees list holds up at the size a bank sync makes it. <img width="1512" height="801" alt="reconciliation-rules" src="https://github.com/user-attachments/assets/6e3ad2f4-884b-41fa-a569-fdc966b20aba" /> ## Features - **Payments match the invoices they settle.** Every transaction that comes in, whether synced, imported or typed by hand, is checked against open invoices and linked when the

  4. v0.15.1v0.15.1Sep 6, 2026

    In this release we rebuilt the dashboard's hero card around the balance you can actually spend, added a way to keep a transaction in your balance while leaving it out of reports, and gave the rules list the filters it was missing. Securo now speaks Japanese, Hindi and Greek. On the fixes side, a credit-card bill stopped dropping purchases that the reporting filter excludes, amount fields honour the number format you configured, and the rate limiter can tell clients apart when it sits behind a reverse proxy. ## Features - **The dashboard leads with available balance.** The hero card answers "what can I spend" first and breaks the figure down per account, with net worth, the month's flow and the savings rate beside it instead of one total standing alone. Closes #691, by @vhsantos26 (#785) 🎉 - **Keep a transaction out of reports without hiding it.** A new toggle leaves the row in the ledger and in the account balance but drops it from income and expense figures, for a work expense put on a personal card or anything else that is not really your spending. By @gabbanaesteban (#675) 🎉 - **The rules list filters.** Search by name and narrow by category, status or action, so a long rule

  5. v0.15.0v0.15.0Sep 1, 2026

    In this release we added an invoicing ledger to workspaces that track work: you can write an invoice, issue it with a number, render it as a document and a PDF, share it through a link anyone can open, and settle it against the money that actually landed in an account. Alongside it, the dashboard's category widget now counts pending spend the same way its drill-down does, Enable Banking no longer imports the same transactions over and over when a provider paginates in a loop, and Securo speaks Slovak and handles Turkish lira and Azerbaijani manat. <img width="1200" height="747" alt="securo-invoices-en" src="https://github.com/user-attachments/assets/7e00c617-ad45-4f47-9a55-ed6470ad4af9" /> ## Features - **An invoicing ledger.** Workspaces that track work get a receivables side: draft an invoice from line items, issue it to assign a number, and follow it through open, partly paid, paid, overdue and uncollectible. The list carries an aging breakdown, filters by state and fiscal year, and totals what is outstanding, overdue and received this month (#718) - **Invoices render as a document and a PDF.** Issuer block, client block, line items, payment details and a footer note

Code frequency

additions and deletions
+36.1K-36.1KWeek of 2026-03-08: +34,179 linesWeek of 2026-03-08: -72 linesWeek of 2026-03-15: +9,863 linesWeek of 2026-03-15: -122 linesWeek of 2026-03-22: +6,592 linesWeek of 2026-03-22: -345 linesWeek of 2026-03-29: +6,079 linesWeek of 2026-03-29: -257 linesWeek of 2026-04-05: +8,881 linesWeek of 2026-04-05: -220 linesWeek of 2026-04-12: +3,747 linesWeek of 2026-04-12: -345 linesWeek of 2026-04-19: +7,672 linesWeek of 2026-04-19: -568 linesWeek of 2026-04-26: +5,769 linesWeek of 2026-04-26: -157 linesWeek of 2026-05-03: +11,934 linesWeek of 2026-05-03: -470 linesWeek of 2026-05-10: +19,357 linesWeek of 2026-05-10: -359 linesWeek of 2026-05-17: +3,243 linesWeek of 2026-05-17: -579 linesWeek of 2026-05-24: +18,642 linesWeek of 2026-05-24: -3,106 linesWeek of 2026-05-31: +7,198 linesWeek of 2026-05-31: -783 linesWeek of 2026-06-07: +7,436 linesWeek of 2026-06-07: -709 linesWeek of 2026-06-14: +6,781 linesWeek of 2026-06-14: -533 linesWeek of 2026-06-21: +2,859 linesWeek of 2026-06-21: -53 linesWeek of 2026-06-28: +3,565 linesWeek of 2026-06-28: -287 linesWeek of 2026-07-05: +4,688 linesWeek of 2026-07-05: -375 linesWeek of 2026-07-12: +970 linesWeek of 2026-07-12: -238 linesWeek of 2026-07-19: +4,591 linesWeek of 2026-07-19: -252 linesWeek of 2026-07-26: +6,731 linesWeek of 2026-07-26: -408 linesWeek of 2026-08-02: +12,378 linesWeek of 2026-08-02: -5,182 linesWeek of 2026-08-09: +6,655 linesWeek of 2026-08-09: -1,568 linesWeek of 2026-08-16: +15,665 linesWeek of 2026-08-16: -1,505 linesWeek of 2026-08-23: +9,503 linesWeek of 2026-08-23: -611 linesWeek of 2026-08-30: +36,128 linesWeek of 2026-08-30: -2,328 linesWeek of 2026-09-06: +20,057 linesWeek of 2026-09-06: -1,237 linesWeek of 2026-09-13: +4,396 linesWeek of 2026-09-13: -506 linesWeek of 2026-09-20: +29,173 linesWeek of 2026-09-20: -1,854 linesWeek of 2026-09-27: +0 linesWeek of 2026-09-27: -0 linesMar 8, 2026Sep 27, 2026
+314.7K lines added, -25K removed over the last year.

Commits per week

last 52 weeks
420Week of 2025-10-04: 0 commitsWeek of 2025-10-11: 0 commitsWeek of 2025-10-18: 0 commitsWeek of 2025-10-25: 0 commitsWeek of 2025-11-01: 0 commitsWeek of 2025-11-09: 0 commitsWeek of 2025-11-16: 0 commitsWeek of 2025-11-23: 0 commitsWeek of 2025-11-30: 0 commitsWeek of 2025-12-07: 0 commitsWeek of 2025-12-14: 0 commitsWeek of 2025-12-21: 0 commitsWeek of 2025-12-28: 0 commitsWeek of 2026-01-04: 0 commitsWeek of 2026-01-11: 0 commitsWeek of 2026-01-18: 0 commitsWeek of 2026-01-25: 0 commitsWeek of 2026-02-01: 0 commitsWeek of 2026-02-08: 0 commitsWeek of 2026-02-15: 0 commitsWeek of 2026-02-22: 0 commitsWeek of 2026-03-01: 0 commitsWeek of 2026-03-08: 18 commitsWeek of 2026-03-15: 8 commitsWeek of 2026-03-22: 13 commitsWeek of 2026-03-29: 15 commitsWeek of 2026-04-05: 8 commitsWeek of 2026-04-12: 12 commitsWeek of 2026-04-19: 22 commitsWeek of 2026-04-26: 12 commitsWeek of 2026-05-03: 16 commitsWeek of 2026-05-10: 8 commitsWeek of 2026-05-17: 14 commitsWeek of 2026-05-24: 12 commitsWeek of 2026-05-31: 25 commitsWeek of 2026-06-07: 25 commitsWeek of 2026-06-14: 15 commitsWeek of 2026-06-21: 4 commitsWeek of 2026-06-28: 14 commitsWeek of 2026-07-05: 14 commitsWeek of 2026-07-12: 7 commitsWeek of 2026-07-19: 12 commitsWeek of 2026-07-26: 11 commitsWeek of 2026-08-02: 24 commitsWeek of 2026-08-09: 28 commitsWeek of 2026-08-16: 26 commitsWeek of 2026-08-23: 24 commitsWeek of 2026-08-30: 42 commitsWeek of 2026-09-06: 12 commitsWeek of 2026-09-13: 28 commitsWeek of 2026-09-20: 40 commitsWeek of 2026-09-27: 0 commitsOct 4, 2025Sep 27, 2026
509 commits in the last 52 weeks.

When work happens

weekday and hour
SunMonTueWedThuFriSat036912151821Sun 0:00 — 3 commitsSun 1:00 — 0 commitsSun 2:00 — 0 commitsSun 3:00 — 0 commitsSun 4:00 — 0 commitsSun 5:00 — 0 commitsSun 6:00 — 1 commitsSun 7:00 — 1 commitsSun 8:00 — 1 commitsSun 9:00 — 0 commitsSun 10:00 — 0 commitsSun 11:00 — 1 commitsSun 12:00 — 0 commitsSun 13:00 — 0 commitsSun 14:00 — 1 commitsSun 15:00 — 2 commitsSun 16:00 — 2 commitsSun 17:00 — 5 commitsSun 18:00 — 3 commitsSun 19:00 — 3 commitsSun 20:00 — 5 commitsSun 21:00 — 2 commitsSun 22:00 — 6 commitsSun 23:00 — 3 commitsMon 0:00 — 0 commitsMon 1:00 — 0 commitsMon 2:00 — 0 commitsMon 3:00 — 0 commitsMon 4:00 — 1 commitsMon 5:00 — 2 commitsMon 6:00 — 0 commitsMon 7:00 — 8 commitsMon 8:00 — 3 commitsMon 9:00 — 3 commitsMon 10:00 — 2 commitsMon 11:00 — 9 commitsMon 12:00 — 12 commitsMon 13:00 — 9 commitsMon 14:00 — 5 commitsMon 15:00 — 7 commitsMon 16:00 — 7 commitsMon 17:00 — 4 commitsMon 18:00 — 7 commitsMon 19:00 — 9 commitsMon 20:00 — 1 commitsMon 21:00 — 0 commitsMon 22:00 — 10 commitsMon 23:00 — 4 commitsTue 0:00 — 2 commitsTue 1:00 — 1 commitsTue 2:00 — 0 commitsTue 3:00 — 2 commitsTue 4:00 — 3 commitsTue 5:00 — 4 commitsTue 6:00 — 2 commitsTue 7:00 — 3 commitsTue 8:00 — 1 commitsTue 9:00 — 0 commitsTue 10:00 — 6 commitsTue 11:00 — 11 commitsTue 12:00 — 3 commitsTue 13:00 — 5 commitsTue 14:00 — 3 commitsTue 15:00 — 4 commitsTue 16:00 — 9 commitsTue 17:00 — 2 commitsTue 18:00 — 8 commitsTue 19:00 — 3 commitsTue 20:00 — 3 commitsTue 21:00 — 2 commitsTue 22:00 — 5 commitsTue 23:00 — 5 commitsWed 0:00 — 5 commitsWed 1:00 — 1 commitsWed 2:00 — 0 commitsWed 3:00 — 0 commitsWed 4:00 — 1 commitsWed 5:00 — 1 commitsWed 6:00 — 0 commitsWed 7:00 — 1 commitsWed 8:00 — 4 commitsWed 9:00 — 14 commitsWed 10:00 — 13 commitsWed 11:00 — 6 commitsWed 12:00 — 10 commitsWed 13:00 — 7 commitsWed 14:00 — 9 commitsWed 15:00 — 10 commitsWed 16:00 — 4 commitsWed 17:00 — 4 commitsWed 18:00 — 2 commitsWed 19:00 — 8 commitsWed 20:00 — 3 commitsWed 21:00 — 3 commitsWed 22:00 — 2 commitsWed 23:00 — 3 commitsThu 0:00 — 3 commitsThu 1:00 — 0 commitsThu 2:00 — 2 commitsThu 3:00 — 1 commitsThu 4:00 — 1 commitsThu 5:00 — 1 commitsThu 6:00 — 2 commitsThu 7:00 — 2 commitsThu 8:00 — 2 commitsThu 9:00 — 2 commitsThu 10:00 — 4 commitsThu 11:00 — 4 commitsThu 12:00 — 9 commitsThu 13:00 — 7 commitsThu 14:00 — 7 commitsThu 15:00 — 3 commitsThu 16:00 — 4 commitsThu 17:00 — 3 commitsThu 18:00 — 9 commitsThu 19:00 — 7 commitsThu 20:00 — 8 commitsThu 21:00 — 1 commitsThu 22:00 — 3 commitsThu 23:00 — 2 commitsFri 0:00 — 1 commitsFri 1:00 — 0 commitsFri 2:00 — 0 commitsFri 3:00 — 0 commitsFri 4:00 — 0 commitsFri 5:00 — 0 commitsFri 6:00 — 2 commitsFri 7:00 — 1 commitsFri 8:00 — 3 commitsFri 9:00 — 5 commitsFri 10:00 — 3 commitsFri 11:00 — 5 commitsFri 12:00 — 0 commitsFri 13:00 — 2 commitsFri 14:00 — 1 commitsFri 15:00 — 5 commitsFri 16:00 — 7 commitsFri 17:00 — 5 commitsFri 18:00 — 3 commitsFri 19:00 — 0 commitsFri 20:00 — 1 commitsFri 21:00 — 0 commitsFri 22:00 — 1 commitsFri 23:00 — 2 commitsSat 0:00 — 1 commitsSat 1:00 — 0 commitsSat 2:00 — 0 commitsSat 3:00 — 0 commitsSat 4:00 — 0 commitsSat 5:00 — 0 commitsSat 6:00 — 1 commitsSat 7:00 — 0 commitsSat 8:00 — 1 commitsSat 9:00 — 1 commitsSat 10:00 — 2 commitsSat 11:00 — 0 commitsSat 12:00 — 2 commitsSat 13:00 — 2 commitsSat 14:00 — 5 commitsSat 15:00 — 4 commitsSat 16:00 — 2 commitsSat 17:00 — 0 commitsSat 18:00 — 1 commitsSat 19:00 — 7 commitsSat 20:00 — 3 commitsSat 21:00 — 2 commitsSat 22:00 — 0 commitsSat 23:00 — 2 commits
Commit volume by weekday and hour (UTC). Larger dots mean more commits.
DateListRankStars gained
Sep 18, 2026monthly#18+1,897
Sep 17, 2026monthly#18+1,897
Aug 28, 2026weekly#9+617
Aug 27, 2026weekly#9+617