Security & compliance

Built on regulated Open Banking rails

Bank connections are consent-based, credential-free and encrypted end to end — so your finance team and your developers can trust the data.

PSD2 & Open Banking

Connections run on licensed, regulated Open Banking providers under PSD2 — not screen-scraping. Access is consent-based and revocable.

OAuth 2.0 & encryption

Token-based authentication with TLS in transit. Access tokens are short-lived and scoped to exactly what each integration needs.

Consent & control

Every connection is explicitly authorised by the account holder at their bank, and can be withdrawn at any time.

No stored credentials

We never see or store bank login credentials. Authentication happens directly with the bank through the Open Banking flow.

Data minimisation

We request only the account and transaction data your integration needs, normalised into one consistent shape.

Reliable infrastructure

Runs on monitored, access-controlled infrastructure with a sandbox environment to validate every change before production.

Questions about security or compliance?

We're happy to walk your team through how connections, consent and data handling work for your use case.