Self-hosted service
securo-finance/securo avatar
securo-finance/securo

Securo: Self-Hosted Personal Finance Manager with Bank Sync and OIDC

Open-source personal finance manager. Self-hosted, privacy-first.

3,886 stars509 forksPythonAGPL-3.0

At a glance

What is it?
Securo is an open-source personal finance manager that runs on your own server, providing transaction management, budgets, goals, and bank sync for European, US, and Brazilian financial institutions. It is built for engineers and self-hosters who want full visibility into their finances without sending data to a third-party SaaS.
Who is it for?
Securo is a strong fit for engineers and self-hosters who already run Docker-based infrastructure and want a complete finance manager with real bank sync rather than manual import. It is a poor fit for anyone who needs a hosted or cloud-synced solution, or who requires mobile-first offline access: the README does not document an offline mode or a native mobile app.
Can I use it commercially?
Yes, with strict conditions. AGPL-3.0 is a network copyleft licence: if people use a modified version over a network, for example as a hosted service, you must offer them its source code under the same licence.
Is it still maintained?
Yes. The repository last received commits 1 day ago.
What is it written in?
Mainly Python, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.

Editorial analysis

Finance Management Without a Third-Party Service Between You and Your Data

Cloud-based personal finance tools (whether aggregators like Mint or budgeting apps like YNAB) require you to hand over bank credentials or OAuth tokens to a company that aggregates your financial data on their infrastructure. Securo takes the opposite approach: it runs entirely on your own server, stores everything in a PostgreSQL database you control, and connects to banks through sync providers whose credentials you configure yourself.

The project targets engineers and privacy-conscious individuals who are already comfortable with Docker and want a self-hosted alternative that does not compromise on features. It includes transaction management with search and filters, a file import pipeline (OFX, QIF, CAMT, and CSV), an auto-categorization rules engine, recurring transactions, budgets, goals and savings targets, asset management with valuation tracking, and reports covering net worth and income vs expenses.

Multi-user support means a household or a small team can share one instance, with an admin panel and registration controls to manage access. Two-factor authentication (TOTP) with brute-force protection and OIDC login support are both included, so the authentication story is solid without needing an external identity proxy.

Python Backend, PostgreSQL, and a Bank Sync Layer Built on Three Providers

Securo's backend is written in Python and uses PostgreSQL as its database. The docker-compose.yml wires a backend service, a frontend service, and a db service together. The SECRET_KEY environment variable must be set in production; the development compose file ships a placeholder value (dev-secret-change-in-production) that must be replaced before any internet-facing deployment.

The bank sync layer is the most architecturally significant part. Securo does not build its own bank connection infrastructure. Instead, it integrates with three separate providers: Pluggy for Brazilian banks, Enable Banking for approximately 2500 European PSD2-connected banks, and SimpleFIN for US and international banks using an open read-only protocol. Each provider auto-registers when its credentials are present in the environment file, so you can run one, two, or all three simultaneously.

The AI Agents feature is listed as optional and provides a self-hosted large language model chat interface with tool-use over your financial data, plus a per-agent RAG knowledge base. The README does not document which models or LLM server it expects, so this feature requires additional research before enabling it.

Installing Securo on Linux, macOS, or Windows

On Linux and macOS, the README provides a one-line installer that handles Docker installation if neither Docker nor Podman is present:

bash
curl -fsSL https://usesecuro.com/install.sh | bash

On Windows, install Docker Desktop first, then clone the repository and start the stack:

bash
git clone https://github.com/securo-finance/securo.git && cd securo
docker compose up --build

Once running, open http://localhost:3000 and create an account. The .env.example file documents the available variables. At minimum, set SECRET_KEY before exposing the instance to any network:

bash
SECRET_KEY=change-me-in-production

The bank sync providers each require their own credentials added to .env before restart. Pluggy requires PLUGGY_CLIENT_ID and PLUGGY_CLIENT_SECRET. Enable Banking requires ENABLE_BANKING_APP_ID and a PEM private key file saved to the ./secrets/ directory. SimpleFIN requires only SIMPLEFIN_ENABLED=true, since each bank connection uses its own single-use Setup Token generated from the SimpleFIN Bridge.

Bank Sync in Detail: Regional Coverage Gaps and Free-Tier Constraints

The three sync providers cover different geographies, and none covers all global banks.

Pluggy covers Brazilian banks. Sign up at pluggy.ai, add the client ID and secret to .env, and configure the OAuth redirect URI. Pluggy is a paid commercial service.

Enable Banking covers roughly 2500 European banks through the PSD2 open banking regulation. Its free tier has a significant constraint documented in the README: you must pre-link the accounts you want to import inside the EB portal before connecting from Securo. Skipping that step causes the connection to return no accounts, and Securo surfaces a banner with a link to the portal. The free tier also requires HTTPS for production use, which means local development needs a tunnel such as ngrok or cloudflared.

SimpleFIN is an open, read-only protocol primarily for US and international banks. It requires no API key; each connection uses a single-use Setup Token from the SimpleFIN Bridge. A sandbox with free demo tokens is available for testing without a real bank account.

Banks outside these three regions (for example, most of Asia, Africa, and Latin America outside Brazil) have no documented sync path. Manual import via OFX, QIF, CAMT, or CSV files is the fallback.

OIDC Authentication and SSO-Only Mode

Securo supports delegating login to any standard OIDC provider, including Authentik and Pocket ID. To enable it, create a confidential application in your provider, register the redirect URI:

bash
OIDC_ENABLED=true
OIDC_PROVIDER_NAME=Pocket ID
OIDC_DISCOVERY_URL=https://id.example.com/.well-known/openid-configuration
OIDC_CLIENT_ID=securo
OIDC_CLIENT_SECRET=your-client-secret

Once OIDC is configured, you can also enable SSO-only mode by setting LOCAL_AUTH_ENABLED=false. In this mode, Securo disables local password login, public registration, password reset, new passkey registration, and new TOTP setup. Securo enforces a safety check: it only starts in SSO-only mode when OIDC_ENABLED, OIDC_CLIENT_ID, and OIDC_DISCOVERY_URL are all configured, preventing a misconfiguration that would leave the instance with no usable login method.

On a fresh OIDC-only instance, the README warns that the first account must be provisioned through OIDC with OIDC_AUTO_REGISTER=true and OIDC_SYNC_ROLES=true, with one of the OIDC_ADMIN_ROLES values included in the identity's roles claim. Disabling auto-registration before at least one admin account exists locks you out.

Where Securo Falls Short

Securo has limitations worth knowing before adopting it.

Bank coverage is regional and provider-dependent. If your bank is not in Brazil, Europe (PSD2), or the US/international SimpleFIN network, there is no automated sync path. You will need to export transactions from your bank in a supported format and import them manually.

The README does not document an offline mode or a native mobile application. Securo is a web app: it requires a running server and a network connection. Travelers who want to log expenses in areas without reliable connectivity need a separate solution.

The AI Agents feature is described in the README but the configuration details for the LLM backend are not documented there. Setting it up requires reading additional documentation at docs.usesecuro.com.

Finally, the application is early in its release cycle: the current version is v0.16.2. The data model or import format could change in ways that require migration steps between versions.

Securo vs Actual Budget: Sync-First vs Local-First Budgeting

Actual Budget is an open-source personal finance application with a local-first architecture that stores data in SQLite files you control. It focuses on envelope budgeting and runs on Windows, macOS, Linux, and the web. Actual does not include built-in bank sync in its open-source release; sync requires a separate service.

Securo's defining feature is its built-in bank sync layer with three provider integrations out of the box. If automated transaction import from your bank is the primary requirement, Securo has a more complete answer than Actual's base open-source release.

The trade-off is operational: Securo requires PostgreSQL and a running web server, while Actual can run entirely from a desktop application with a local file. For users who want a single-machine setup without a database server, Actual is a lighter option. For self-hosters already running Docker stacks, Securo's additional weight is marginal.

Maintenance Status and the AGPL-3.0 License Obligation

The last push to the repository was on 2026-09-25, and the most recent release is v0.16.2, also dated 2026-09-25. Three releases shipped in September 2026 alone (v0.16.0 on September 17, v0.16.1 on September 22, v0.16.2 on September 25), indicating active development.

The project is licensed under AGPL-3.0. This license is stricter than GPL for hosted services: if you run a modified version of Securo and make it available to users over a network, you must make your source modifications available to those users. For a private instance used only by your household or a closed team, AGPL behaves like GPL: you can modify and run it without publishing changes. Anyone offering Securo as a hosted service to third parties must publish their modifications.

For Docker deployments, staying current means pulling the updated images and running docker compose up. The README does not document a database migration rollback process, so testing version upgrades on a copy of production data before applying them to the live instance is the safe approach.

Editorial conclusion

Securo is a strong fit for engineers and self-hosters who already run Docker-based infrastructure and want a complete finance manager with real bank sync rather than manual import. It is a poor fit for anyone who needs a hosted or cloud-synced solution, or who requires mobile-first offline access: the README does not document an offline mode or a native mobile app. The AGPL-3.0 license is the main legal consideration before deploying: if you build a hosted service on top of Securo and offer it to others, you must release your modifications under the same license. Verify that your preferred bank is covered by one of the three sync providers (Pluggy, Enable Banking, or SimpleFIN) before committing to the setup.

Frequently asked questions

What is Securo?

Securo is an open-source, self-hosted personal finance manager that runs on your own server via Docker. It provides transaction management, budgets, goals, asset tracking, and bank sync for European, US, and Brazilian financial institutions, all without sending financial data to a third-party service.

How does Securo compare to Actual Budget?

Securo includes built-in bank sync through Pluggy, Enable Banking, and SimpleFIN, while Actual Budget's open-source release focuses on local-first envelope budgeting without bundled bank sync. Securo requires PostgreSQL and a Docker stack; Actual can run as a lighter desktop application.

Does Securo support multi-currency transactions?

Yes. The README lists multi-currency support with automatic FX conversion as a built-in feature. The README does not document which FX data source it uses for conversion rates.

Official sources

  1. License: AGPL-3.0
  2. Project website
  3. README
  4. Releases
  5. securo-finance/securo on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/securo-finance-securo.svg)](https://hysenlabs.com/projects/securo-finance-securo)