Skip to content
Security & Privacy

Your financial data handled with care

We built our security model around one principle: your data should only go where it needs to go to make the product work, and nowhere else.

How we handle your data

Your credentials never touch our servers

When you connect a bank or investment account, your login credentials go directly to Plaid, not to us. Plaid sends back an encrypted access token. We never see your username or password.

Read-only access

All Plaid connections are read-only. We can see your transactions and balances. We cannot move money, initiate transfers, or make any changes to your accounts.

Encryption at rest and in transit

All data in transit is protected with TLS 1.2+. Plaid access tokens and OAuth credentials stored on our servers are encrypted with AES-256-GCM.

We do not sell your data

Your financial data is used only to operate the product you signed up for. We do not sell it, share it with advertisers, or use it for any purpose beyond providing the service.

Marketing website (vaultcompass.io)

The public site is served over HTTPS. Contact and waitlist submissions are processed by Formspree. We use Plausible Analytics for aggregate traffic and limited, action-focused events, not ad profiling. Full detail is in our Privacy Policy.

  • TLS for all pages; security disclosures: security@vaultcompass.io
  • security.txt for coordinated disclosure

Per-product details

Prismfolio

Chrome Extension

Local analysis by default. Optional account sync uses read-only Plaid and Google Sign-In.

  • Free tier: on broker pages, portfolio data is read from the page you already opened and analyzed locally; optional sign-in supports up to 3 accounts and 1 read-only Plaid sync
  • Plus tier: Google Sign-In via Chrome Identity API. Your Google credentials are authenticated through Google's own infrastructure and never touch our servers
  • Plus tier: unlimited read-only Plaid sync. We receive holdings and balance data only, never banking credentials
  • JWT access token stored in Chrome extension local storage, inaccessible to web pages
  • The extension requests only the permissions required: active tab, brokerage host access, and identity for optional sign-in

Sheetful

Web App

Bank credentials go directly to Plaid. Encrypted tokens and transaction records on our servers; your spreadsheet is the portable copy you own.

  • When linking your bank, credentials are entered directly into Plaid's interface. They are encrypted in your browser and passed to Plaid, never to us
  • Plaid sends us a read-only access token, which we encrypt with AES-256-GCM at rest
  • Transaction records are stored encrypted to power sync, categorization, and the in-app dashboard before rows are written to your sheet
  • OAuth tokens (Google or Microsoft) are stored encrypted and scoped to write access for your connected spreadsheet only
  • All API communication over TLS 1.2+

Powered by Plaid

Bank and investment connectivity across all our products is powered by Plaid, used by thousands of financial apps. Plaid connects to over 12,000 financial institutions and is trusted by millions of users. Your credentials go directly to Plaid, not to us.

Plaid security overview →

SOC 2 roadmap

We are working toward SOC 2 Type I certification. Until then, we document our security controls and make them available to enterprise customers upon request.

Responsible disclosure

Found a security issue? We take reports seriously and respond within 48 hours. We do not pursue legal action against researchers acting in good faith.

security@vaultcompass.io