Security controls, plainly stated.
Your account holds real work — pitches, financials, progress notes, personal reflection. Here are the application protections and requirements that need production evidence.
Application controls and production requirements.
Account and bank-link protection
Bank-link token creation and exchange verify the signed-in session and require two-step authentication. Bank linking is optional and does not authorize payments.
Restricted access
Member records use database access policies and owner checks. Administrative actions require a protected role. We review access rules as features change.
Encrypted bank credentials
Manual bank numbers and Plaid access tokens are encrypted with AES-256-GCM before application storage. Access tokens stay server-side; account displays use masked details.
Secret handling
Integration credentials are stored as managed secrets and used on the server. They are not returned in bank-link responses.
Consent and revocation
Bank linking requires explicit, versioned consent. Removing a connection requests revocation with Plaid and deletes its stored access token after successful revocation.
Production review
Our written policies require access reviews, administrator MFA, vulnerability management, incident response, vendor review and evidence of infrastructure encryption. These organizational controls need operational verification; policy documents alone do not prove completion.
Privacy in context.
Understand the purpose of your information and who processes it.
Purpose-limited bank data
Bank data supports the connection and verification you request, not marketing or advertising.
Clear service-provider disclosures
AI, payment, booking and communication tools may process information needed for their services. Review our Privacy Policy and each provider's terms.
Not end-to-end encrypted
The platform processes messages and other content to provide its services. We do not describe those services as end-to-end encrypted.
How your data is actually protected.
In transit
Production bank integrations use HTTPS. Specific infrastructure TLS versions, cipher settings and certificate controls require provider evidence.
Application bank-data encryption
Bank numbers and Plaid access tokens use AES-256-GCM with a server-side managed encryption secret. Database, media and backup encryption and key-rotation procedures require separate operational evidence.
Bank tokens
Plaid access tokens are not returned to the browser. Signed webhook verification authenticates item-update notifications.
What we are measured against.
Written requirements and verified certifications are different. We do not imply an audit has been completed.
- 01
Plaid production readiness
Consumer MFA, encryption, consent and access-control requirements must be tested and evidenced in production before we represent them as verified to Plaid. Production approval is not established by publishing this page.
- 02
Independent certifications
This page does not claim a completed SOC 2 report, HIPAA certification or independent security audit. Any certification requires separate, verified evidence.
- 03
Privacy rights
Available rights vary by jurisdiction. Use the Data Rights Center or contact us to request access, correction, restriction or deletion.
Controls you hold, not us.
Access and correction
Edit your profile and request access or export through the Data Rights Center.
Privacy choices
Manage optional analytics, communications and AI-memory preferences.
Deletion and revocation
Request deletion, subject to legal retention, and remove optional Plaid connections from your bank page.
Exercise any of these in one click from your Data Rights Center— including consent switches, data requests, erasure, a Business Associate Agreement request, and questions about disclosures.
To report a vulnerability or request a security review, reach us through the contact channels on the About page. We acknowledge reports within two business days and never pursue good-faith researchers.
Create your account.
Individualized AI support, saved work, and privacy controls that are actually yours.
