Security & Privacy Standard

Bank-level security.
Built into every layer.

Your financial data is sacred. Trupence uses read-only multi-aggregator API connections via Quiltt, bank-grade encryption, and zero data selling to protect your privacy.

Quiltt Multi-Aggregator

Connect to over 12,000 financial institutions through Quiltt—a unified multi-aggregator platform bridging Plaid, Finicity, MX, and direct bank APIs into a single tokenized integration.

Zero Password Access

You log directly into your financial institution's official site in an isolated window. Trupence never sees, accesses, or stores your bank username, password, or 2FA codes.

Strictly Read-Only Access

All connections authorized with Trupence are strictly read-only. We have zero money-movement permissions, transfer capabilities, or debit authorizations. Your money stays untouched inside your bank.

Zero Data Selling

Unlike free budgeting apps that profit by selling user transaction history or serving targeted financial ads, Trupence is funded purely by subscriptions. You are our customer—not the product.

Trupence connects securely to over 12,000 financial institutions using Quiltt—a unified financial multi-aggregator platform that routes connections through leading data networks including Plaid, Finicity, MX, and direct Open Banking APIs.

When linking an account, you log directly into your bank's official website in an isolated popup window. Once authorized, your bank issues an encrypted, read-only API access token.

Zero Credential Access: Your bank username, password, and 2FA codes are entered directly on your bank's portal. They are never sent to, seen by, or stored on Trupence servers.

No, absolutely not. All account connections authorized with Trupence are strictly read-only.

Trupence can only view transaction history and current account balances to populate your financial command center. We have zero money-movement permissions, transfer capabilities, or debit authorizations. Your money stays untouched inside your bank accounts.

Never. We maintain a strict policy against selling user data.

Unlike free budgeting tools that monetise by selling transaction data or displaying targeted financial ads, Trupence is funded purely by subscription revenue. You are our customer—not the product.

We protect your financial information using bank-grade security protocols:

  • Bank-Grade 256-Bit Encryption: All database storage and account tokens are encrypted at rest with AES-256 encryption keys.
  • Encrypted Connections: All data transferred between your browser, our servers, and Quiltt API endpoints uses modern TLS encryption.
  • Strict Account Isolation: Database records are bound strictly to your verified account identity, ensuring no other account can access your records.

Trupence offers fast, secure, and flexible sign-in options:

  • Sign in with Google: Log in instantly with your Google account using secure OAuth 2.0 with PKCE protection.
  • Passwordless Magic Links: Receive a single-use login link directly in your email.
  • Two-Factor Protection (2FA): Support for Google Authenticator, 1Password, Authy, and biometric keys (Touch ID, Face ID, Windows Hello).

For security professionals reviewing our technical stack:

  • Multi-Aggregator Layer: Integrated via Quiltt unified API infrastructure routing to Plaid, Finicity, MX, and Open Banking direct tokens.
  • Encryption Standards: AES-256-GCM field-level data encryption with HSM key management; TLS 1.3 in transit with strict HSTS.
  • Database Security: PostgreSQL Row-Level Security (RLS) enforcing session token tenant boundaries on every database query.
  • Password Hashing: Argon2id key derivation with per-user cryptographic salts.
  • Session Management: Short-lived JWTs delivered in HttpOnly, Secure, SameSite=Strict cookies to prevent client-side XSS extraction.