Security

Read-only, architecturally. Every connection is read-only. Nothing in this system can move money, place a trade, or instruct an institution. It is not a permission setting. It is what the system is capable of.

The detail

How the record is held.

Encryption
AES-256 at rest. TLS 1.2 and above in transit. Documents encrypted individually.
Credentials
Institution credentials are held by the aggregation networks under their own security regimes, never by us, and never in a form we can read.
Access
Multi-factor authentication. Per-user, per-entity permissions. Complete audit log of every access event, visible to you.
AI
The connection transmits positions, values, history and cash flows. It does not transmit credentials or documents. Disable it for one user or the whole account, in one action.
Your data
Never sold. Never shared. Never used to train any model. Full export on request at any time, including the day you leave.
If we disappear
Your record exports in full, in open formats, on demand, with no notice period and no exit fee. A system of record that holds you hostage is not a system of record.