← Back to Cresara

Security, in detail.

When you connect financial accounts to a service, you have every right to ask exactly what they do with your data. This page tells you, specifically.

Your credentials, never on our servers

When you connect a brokerage or bank, you enter your credentials into Plaid — not into Cresara. Plaid is the same trusted infrastructure used by Robinhood, Venmo, Coinbase, and hundreds of other regulated financial apps.

Plaid returns to us only an access token — an opaque string that lets us request your balances, never your password. If you revoke access in Plaid's portal, our access ends immediately.

Encryption

At rest

All Plaid access tokens and sensitive fields are encrypted with AES-256-GCM before being written to our database. The encryption key is stored separately in our server environment.

In transit

Every connection to Cresara is over HTTPS. The .app top-level domain enforces HTTPS at the browser level — the site won't even load without it.

Authentication

We don't use passwords. Sign-in is via a one-time code sent to your verified email. Sessions expire after 30 days of inactivity. Compromised email means compromised account — so we recommend strong 2FA on your email provider.

Infrastructure

What we don't do

Reporting an issue

If you discover a security vulnerability or have a security concern, email security@cresara.app. We'll acknowledge within 24 hours and work to resolve quickly. Cresara is operated by Cresara LLC, Delaware, United States.

Honest limitations

We want to be transparent about what we're not (yet):

For these reasons, we recommend Cresara as a tracker and overview tool — not as your only record of important financial data. Always retain official statements from your financial institutions.