Skip to main content

Security and your data

Where your data is stored, what Vault can and cannot reach, and who else is involved.

What Vault can reach, and what it cannot

Bank accounts are read-only. Vault can read your balances and transactions. It cannot initiate a payment, move funds, or change anything at your bank. There is no code path that could — the access itself does not permit it.

We never see your banking credentials. You authorise the connection at your bank's own site, through a licensed open banking provider. Your login details never pass through us.

Crypto wallets are read-only too. You add a public address, and we read what the blockchain already publishes about it. We do not hold private keys and cannot move any assets.

Where your data lives

Our database and application run in the European Union — Frankfurt, Germany.

Data is encrypted in transit and at rest. Access between customers is separated at the database level, so one customer's data is not reachable from another's account, regardless of what the application does.

Access to production systems is limited to authorised people and requires authentication.

Backups

Backups run automatically, with point-in-time recovery — meaning we can restore the database to a specific moment rather than to the last nightly snapshot.

In practice that matters if something goes wrong on our side: the window of work that could be lost is minutes rather than a day.

Two-step verification

You can enable two-step verification on your account from your profile settings. We recommend it, particularly for the workspace owner.

Who else is involved

We work with a small number of service providers — for hosting, payments, bank connections, email and support. Each of them processes data on our instructions and under contract.

The full list is public, with what each one does and where it is located: usevault.ai/subprocessors

We give at least 30 days' notice before adding a new one.

What we do not do

  • We do not sell your data.

  • We do not share it for advertising.

  • We do not use it to train machine learning models, and we do not send your financial data to any AI provider.

If that changes, we will update our policy and tell you in advance.

Your data belongs to you

You can export your transactions at any time while your workspace is active.

If you close your account, you have 30 days to request an export. After that the workspace and its data are permanently deleted from our systems.

The documents

Everything above is written into our legal terms, which are public:

If your legal or security team needs anything else — a signed copy of the DPA, answers to a security questionnaire — write to us and we will provide it.

Did this answer your question?