Your financial life is personal. Paiso is built on a simple idea: your data is there to serve you, not to be monetized. This page explains how we protect your account and your information, and the choices you have.
At a glance
- We never sell your data and don’t use it for advertising.
- Read-only bank connections. Paiso can’t move money.
- We never see your bank login. Connections go through Plaid.
- Encrypted in transit and at rest, with an extra layer of encryption for the most sensitive credentials.
- Two-factor authentication with recovery codes.
- Your data, your call: delete it permanently yourself, any time.
Protecting your account
- Passwords are never stored. We keep only a one-way hash, produced by a modern, memory-hard hashing algorithm chosen to resist large-scale cracking. The same password rules apply everywhere a password can be set or changed.
- Two-factor authentication. Turn on a second step at sign-in using any authenticator app. You get one-time recovery codes in case you lose your device, and we store only hashes of those codes. Two-factor applies however you sign in, including with Google, Apple, or LinkedIn.
- Sign in your way. Use an email and password, or sign in with Google, Apple, or LinkedIn so there’s one less password to manage.
- Verified sign-ups and bot protection. New accounts confirm their email address, and our sign-up and password-reset forms are protected against automated abuse.
- Brute-force protection. Repeated failed sign-in attempts are slowed down and throttled, both in the application and at the network edge before they reach us.
- Sessions you can trust. Sign-in sessions are short-lived and renewed with a per-device credential that scripts on the page cannot read and that travels only over HTTPS. Each renewal replaces the previous one, and a credential that is reused after being replaced has its session revoked.
- Safe password resets. Reset links are single-use and expire. Resetting or changing your password signs you out everywhere else.
Encryption
- In transit. All connections to Paiso use HTTPS (TLS). Browsers are instructed to always use a secure connection (HTTP Strict Transport Security).
- At rest. Our production servers store data on encrypted disks.
- An extra layer for the most sensitive secrets. The tokens that let Paiso refresh your linked accounts, and the secrets behind your two-factor authentication, are also encrypted inside the application before they’re saved, with keys kept separate from the database. The service is configured to refuse to start in production if those keys are missing.
Connecting your accounts, safely
Paiso uses Plaid, which powers financial connections for thousands of apps, to link banks, cards, loans, and investment accounts. Linking is always optional. You can use Paiso entirely with data you enter or import yourself.
- We never see your credentials. You sign in to your bank inside Plaid’s secure window. Your bank username, password, and security answers never reach Paiso.
- Read-only access. Paiso requests only the permissions needed to read balances, transactions, investments, and loan details. We don’t use features that move money, make payments, or initiate transfers.
- Disconnect any time. When you disconnect an account, or delete your Paiso account, we tell Plaid to revoke our access. If that request can’t get through right away, we keep retrying automatically until it does.
Payments
Subscriptions are processed by Stripe, a PCI DSS Level 1 certified payment provider. You enter your card details directly into Stripe’s secure form. Your card number never touches Paiso’s servers. We keep only a reference to your subscription and its status.
Infrastructure and operations
- No open doors. Our production servers accept no direct connections from the internet. All traffic reaches them through an encrypted Cloudflare tunnel, behind Cloudflare’s network protection.
- Separated environments. Production is fully isolated from our testing environment, with separate servers, databases, and secrets. Testing uses only sandbox bank and payment connections and never touches real customer data.
- Secrets stay secret. Passwords, API keys, and encryption keys are never stored in our source code. They’re kept only on the servers that need them.
- Verified webhooks. Notifications from Plaid and Stripe are checked for authentic signatures before we act on them.
- Tested before release. Every production release must pass our automated test suite before it can deploy.
Who can see your data
- Your data is walled off from everyone else’s. Every request is tied to your signed-in account, and access to each record is checked against it. Dedicated automated tests attempt to reach other users’ data and confirm the attempts are refused.
- Limited internal access. Only a small number of authorized Paiso team members have administrative access, and only to support and operate the Service. Administrative sign-in is kept separate from regular app sessions, and administrative actions on accounts are recorded in an audit log.
- No impersonation. Staff can’t sign in as you or browse the app as you.
Your privacy, your control
- We don’t sell your data and don’t show ads. Our business is the subscription you choose to pay for.
- No AI training or processing. Your financial data isn’t sent to AI or large-language-model services.
- No tracking. We don’t use advertising cookies, third-party analytics, or session-recording tools in the app.
- Ask for a copy any time. Email us and we will send you a copy of the data we hold about you.
- Delete any time. Permanently delete your account and data, or reset your data while keeping your login, right from Settings. Deleting also disconnects your banks at Plaid and cancels any subscription at Stripe.
Read our Privacy Policy for full details.
Reporting a security issue
We welcome reports from security researchers and users. If you believe you’ve found a vulnerability in Paiso, please email [email protected] with enough detail for us to reproduce it.
- We’ll acknowledge your report within 10 business days and keep you updated as we investigate and fix it.
- If you act in good faith and follow this policy, we won’t pursue legal action against you for your research.
- Please don’t access, change, or delete other people’s data. Use only accounts you own or have permission to test. Don’t degrade the Service for others (no denial-of-service or spam testing), and give us reasonable time to fix an issue before disclosing it publicly.
- We don’t run a paid bug bounty program at this time, but we’re grateful for responsible disclosures and happy to credit you.
Questions?
Contact us at [email protected] for security questions or [email protected] for privacy questions.