Security & Protection

Your financial data is fortress-protected

We use the same security standards as major banks to protect your financial information. Your data is encrypted, secured, and never shared without your permission.

256-bit Encryption
Plaid Secured
SOC 2 Compliant
Biometric Auth

Powered by Plaid's trusted infrastructure

We partner with Plaid, the financial technology company trusted by thousands of apps and millions of users.

What is Plaid?

Plaid is a financial technology company that securely connects your bank accounts to apps like Spense. They're used by major companies like Venmo, Coinbase, and thousands of other financial apps.

When you connect your bank account through Plaid, we only get read-only access to your transaction data—we can never move money or access your banking credentials.

How it keeps you safe

  • Your banking credentials never pass through Spense
  • Read-only access means we can't move or touch your money
  • Bank-level encryption protects all data transfers
  • You can revoke access anytime through your bank

Multiple layers of protection

We secure your data at every level, from your device to our servers

Device Security

  • Face ID and Touch ID authentication
  • App passcode protection
  • Automatic screen privacy protection
  • Local data encryption on device

Data Transmission

  • TLS 1.3 encryption for all communications
  • Certificate pinning prevents man-in-the-middle attacks
  • End-to-end encryption for sensitive data
  • Real-time threat monitoring

Server & Storage

  • SOC 2 Type II compliant infrastructure
  • AES-256 encryption at rest
  • Regular security audits and penetration testing
  • Secure cloud hosting with AWS

What we can't see (and never will)

Your privacy is protected by design. Here's what we intentionally limit ourselves from accessing.

We can't access

  • • Your online banking username or password
  • • Your bank account numbers or routing numbers
  • • Your debit or credit card numbers
  • • Your Social Security Number
  • • The ability to move or transfer your money
  • • Your bank's website or mobile app directly

We only see

  • • Transaction amounts and descriptions
  • • Account names and types (checking, savings, etc.)
  • • Account balances (to help with budgeting)
  • • Merchant names and categories
  • • Transaction dates and pending status
  • • Basic account holder name for verification

Industry compliance & certifications

SOC 2 Type II

Our infrastructure meets the highest standards for security, availability, and confidentiality as defined by the American Institute of CPAs.

GDPR Compliant

We follow European data protection standards, giving you full control over your personal information and the right to data portability.

Have security questions or concerns?

Our security team is here to address any questions about how we protect your financial data.

Contact Security Team

[email protected] • Response within 24 hours