Security and privacy
What you should expect from anything that reads your bank.
This page describes the controls that exist in the deployed product today. Planned work is marked as planned, and nothing here is a certification or a guarantee.
Controls in place
How your data is protected.
Provider logins stay with the provider
Square is connected with OAuth on Square's own page using read-only scopes. Banks are connected through Plaid Link; your bank credentials are entered with Plaid and never reach Zyven.
Read-only by design
Zyven requests read scopes only. It has no ability to initiate payments, transfers or refunds through Square, Plaid or your bank.
Connection keys encrypted at rest
Square and Plaid access tokens are encrypted with AES-256-GCM before they are stored, decrypted only in server memory, and never written to logs or shared with the browser.
Encrypted in transit
All traffic to Zyven uses HTTPS with HSTS. Pages ship a strict Content-Security-Policy and are never embeddable in other sites.
Two-step verification
Owners can turn on authenticator-app (TOTP) two-step verification. It is required before a bank or Square account can be connected.
Sessions you can end
Sessions expire after one hour. Signing out revokes every session for your account at once, and a password reset does the same.
Your business, your data
Every record is scoped to your business. Data is used only to produce your own brief, forecast and answers, and is never sold or shared with advertisers.
Disconnect and delete
You can disconnect Square or a bank at any time; Zyven asks the provider to revoke access and deletes revoked bank data after 90 days. Full account deletion is available on request.
Honest about status
Zyven is not certified against SOC 2, PCI DSS or similar standards today. We describe the controls that exist, mark planned work as planned, and tell pilot businesses exactly what is live before they connect a real account.
Planned
What is not finished yet.
We would rather tell you now than have you discover it later.
- Independent certification (SOC 2 Type I is targeted within 12 months of general launch). Zyven holds no certification today.
- Envelope encryption of connection keys with a managed key service; today keys are protected with an application-managed AES-256-GCM key.
- A dedicated data-processing agreement for pilot businesses that connect live financial data.
Reporting a concern
Found something? Tell us.
Email [email protected] with what you found and how to reproduce it. We acknowledge reports and keep you informed until the issue is resolved. Please do not test against accounts that are not your own.
Related: Privacy policy, Terms of service, Delete your account and data.
Next step
Questions before you connect anything?
Ask us first. We will tell you plainly what is live, what is in testing, and what to expect.