Skip to content

Security and privacy

What you should expect from anything that reads your bank.

This page describes the controls that exist in the deployed product today. Planned work is marked as planned, and nothing here is a certification or a guarantee.

Current status. Zyven is in a controlled early-access phase. Provider connections currently run against Square and Plaid test (sandbox) environments and do not process live bank or payment data unless a business has been admitted to the pilot in writing. Zyven is not a bank and does not hold, move or lend money.

Controls in place

How your data is protected.

  • Provider logins stay with the provider

    Square is connected with OAuth on Square's own page using read-only scopes. Banks are connected through Plaid Link; your bank credentials are entered with Plaid and never reach Zyven.

  • Read-only by design

    Zyven requests read scopes only. It has no ability to initiate payments, transfers or refunds through Square, Plaid or your bank.

  • Connection keys encrypted at rest

    Square and Plaid access tokens are encrypted with AES-256-GCM before they are stored, decrypted only in server memory, and never written to logs or shared with the browser.

  • Encrypted in transit

    All traffic to Zyven uses HTTPS with HSTS. Pages ship a strict Content-Security-Policy and are never embeddable in other sites.

  • Two-step verification

    Owners can turn on authenticator-app (TOTP) two-step verification. It is required before a bank or Square account can be connected.

  • Sessions you can end

    Sessions expire after one hour. Signing out revokes every session for your account at once, and a password reset does the same.

  • Your business, your data

    Every record is scoped to your business. Data is used only to produce your own brief, forecast and answers, and is never sold or shared with advertisers.

  • Disconnect and delete

    You can disconnect Square or a bank at any time; Zyven asks the provider to revoke access and deletes revoked bank data after 90 days. Full account deletion is available on request.

  • Honest about status

    Zyven is not certified against SOC 2, PCI DSS or similar standards today. We describe the controls that exist, mark planned work as planned, and tell pilot businesses exactly what is live before they connect a real account.

Planned

What is not finished yet.

We would rather tell you now than have you discover it later.

  • Independent certification (SOC 2 Type I is targeted within 12 months of general launch). Zyven holds no certification today.
  • Envelope encryption of connection keys with a managed key service; today keys are protected with an application-managed AES-256-GCM key.
  • A dedicated data-processing agreement for pilot businesses that connect live financial data.

Reporting a concern

Found something? Tell us.

Email [email protected] with what you found and how to reproduce it. We acknowledge reports and keep you informed until the issue is resolved. Please do not test against accounts that are not your own.

Related: Privacy policy, Terms of service, Delete your account and data.

Next step

Questions before you connect anything?

Ask us first. We will tell you plainly what is live, what is in testing, and what to expect.