Security

What we can see, what we cannot do, and where it lives.

Plain answers to the questions people ask before they connect a bank.

Bank access is read-only

Cifrova Personal reads your accounts through licensed open-banking providers (Fintable and GoCardless, under PSD2). They hand us a list of movements and balances; there is no way to move money, pay or change anything at the bank through Cifrova. You renew the consent every 90 days at the bank, and you can revoke it there at any moment.

Your data stays in the European Union

Everything runs on servers we operate in the European Union (OVH). Nothing is sold, shared or used to train anything. The only third parties that see data are the ones the product needs: the bank provider, the email service that sends your Sunday email, and Anthropic when an assistant reads a bank line or answers a question.

The assistants see little

When Claude files a movement it sees the bank line and your category names, nothing else. Anthropic does not train on this data. A household can bring its own Anthropic key and switch every assistant off in Settings.

Sign-in without passwords

You sign in with a link sent to your email, valid for minutes, and you can add a second step with an authenticator app. In Cifrova Business the second step is mandatory for everyone.

Secrets are sealed

Bank tokens, keys and anything sensitive are encrypted at rest with a key that lives only on the server. Backups of the business books are encrypted and restored in a drill, not just kept.

Erased when you say so

Leave, and the household is erased: accounts, movements, rules, the lot, with an email that confirms it. A business installation keeps what the law requires for as long as the law requires, and nothing more.

Tell us

Found something? Write to security@cifrova.com or use the address in /.well-known/security.txt. We answer in person.

Security · Cifrova