Trust Center

Security & Trust

How OssFin protects your financial data  ยท  Last updated: July 31, 2026

Overview

OssFin helps you understand your financial life by bringing your accounts into one place. That means we handle sensitive information, and we treat protecting it as a core part of the product โ€” not an afterthought.

We maintain a written information security program aligned to the GLBA Safeguards Rule (16 CFR 314) and structure our controls around the AICPA SOC 2 Trust Services Criteria. This page summarizes how we keep your data safe.

The short version: Your bank credentials are never seen or stored by OssFin โ€” connections run through Plaid's bank-grade API. Sensitive data is encrypted in transit and at rest. We never sell your data, and you can delete everything at any time.

๐Ÿ”’ Encrypted

TLS in transit; sensitive data and account tokens encrypted at rest with AES-256-GCM.

๐Ÿฆ Never your credentials

Bank logins are entered into Plaid, never transmitted to or stored by OssFin.

๐Ÿ—‘๏ธ Your control

Delete your account and all associated data โ€” including bank links โ€” at any time.

๐Ÿšซ Not for sale

We do not sell or rent your personal or financial information.

How your bank connection works

OssFin connects to your financial accounts through Plaid, the same bank-connectivity provider used by many major fintech apps. When you link an account:

Encryption

Access controls & authentication

Infrastructure & monitoring

Resilience & backups

Data privacy & your controls

Subprocessors

We use a small set of established providers to operate OssFin. Each receives only the data necessary for its function.

ProviderPurposeData
PlaidBank & investment connectivityAccount, transaction & holdings data (credentials entered at Plaid, never seen by OssFin)
GoogleSign-in (OAuth)Name, email, profile ID
StripePaymentsName, email, subscription status (card data held by Stripe, not OssFin)
AnthropicAI document analysis & assistantContents of documents you upload for analysis; assistant messages
RailwayApp hosting & databaseStored application data
VercelFrontend hostingStatic assets (no financial data)
ResendTransactional emailEmail address, name, summary figures
SentryError monitoringTechnical error context (PII scrubbed)

Incident response

We maintain a written incident-response plan covering detection, containment, recovery, and notification. In the event of a security incident affecting your information, we will investigate promptly and notify affected users and regulators as required by applicable law.

Compliance posture

OssFin is a personal-finance data aggregation and educational tool. It is not a bank, broker-dealer, or investment adviser, and it does not custody funds, move money, or execute trades.

Report a vulnerability

We welcome responsible disclosure. If you believe you've found a security issue, please email security@ossfin.com with details so we can investigate. Please give us a reasonable opportunity to address the issue before public disclosure.

Security questions?

Evaluating OssFin for a partnership or need to complete a security review? Reach out at security@ossfin.com and we'll be glad to help.