---
title: "BankBridge security: read-only bank access that can never move money"
description: "How BankBridge protects your bank data: read-only access with no way to move money, no stored transactions, AES-256-GCM encrypted tokens, revocation, and deletion when you cancel."
url: "https://bankbridge.money/security"
---
Security

# Read-only. It can never move money.

BankBridge lets your AI agent read your balances, transactions, and investments. It has no way to transfer money, pay a bill, or place a trade, and it doesn’t keep a copy of your financial data. Here is exactly what it can see, what it stores, and how to shut it off.

## Read-only by design

When you connect a bank, BankBridge asks for read access to transactions and, if you have them, investments. Nothing else. There is no payments or transfer permission to grant, so even a compromised server or a misbehaving agent can’t move money.

Your agent gets 12 tools. 11 of them only read data:

-   `list_accounts`: Balances and types for every connected account.
-   `get_account`: Detail lookup for one account by id.
-   `list_transactions`: Transactions filtered by date, amount, category or account (paginated).
-   `search_transactions`: Substring search over transaction name and merchant.
-   `get_spending_summary`: Spending grouped by category, merchant, month or week.
-   `get_recurring_charges`: Detected subscriptions, bills and other recurring charges.
-   `get_monthly_cashflow`: Income vs expenses for a month plus top sources and categories.
-   `get_merchant_history`: Every charge from one merchant plus totals and cadence.
-   `list_categories`: Spending categories present in the user's data.
-   `list_holdings`: Current investment positions with cost basis and gain/loss.
-   `list_investment_transactions`: Buys, sells, dividends, fees and transfers.

The 12th, `connect_bank`, only returns a link. You open it yourself and sign in to your bank; the agent never sees that step.

No tool, for any agent, can:

-   Transfer money or pay anyone
-   Pay a bill or schedule a payment
-   Place, change, or cancel a trade
-   Open, close, or change an account
-   Change your bank password or settings

## What your agent can and can't see

Your agent can see:

-   Account names and types (checking, savings, credit card, brokerage)
-   The last 4 digits of each account number
-   Current and available balances, and credit limits
-   Up to 24 months of transactions: date, description, merchant, amount, category
-   Investment holdings with cost basis, and investment activity (buys, sells, dividends, fees)

Your agent can’t see:

-   Your bank username or password
-   Your full account or routing numbers
-   Anything at a bank you haven't connected

You sign in to your bank inside a secure bank-connection window run by a regulated bank-data provider, the same infrastructure used by Venmo and Robinhood. Your bank credentials go to that provider and your bank. BankBridge and your agent never receive them.

## No transaction storage

Every question your agent asks is fetched live from your bank, sent back to your agent, and dropped. There is no cache of your accounts or transactions to leak.

What BankBridge stores:

Your email address

For sign-in links and billing notices

Subscription status

Plan, status, and period end, from Stripe

Bank connection tokens

Encrypted with AES-256-GCM. One per connected bank

API keys

SHA-256 hashes, plus an AES-256-GCM encrypted copy of your personal key so the dashboard can show it to you again. Connector (OAuth) tokens are stored as hashes only

Call log

Which tool your agent called, when, from which app and IP address, and whether it succeeded. You can see it on the Activity page

What it never stores:

-   Balances
-   Transactions
-   Investment holdings or activity
-   What your agent asked (tool arguments such as search terms or date ranges)
-   What came back (tool results)

## Encryption

Bank connection tokens are encrypted at rest with AES-256-GCM before they reach the database. API keys are stored as SHA-256 hashes, so a copy of the database doesn’t give anyone a working key. All traffic to bankbridge.money is HTTPS only, with HSTS.

## Revoking access

-   Rotate your API key in the dashboard. The old key stops working on its next call.
-   Remove a connector (claude.ai, ChatGPT, and other OAuth apps) in that app. Each connector has its own token, separate from your API key.
-   Disconnect a bank on the Banks page. The connection is revoked with the bank-data provider and deleted right away, so no agent can read that bank anymore.
-   Delete your account from Settings to do all of the above at once.

The Activity page shows every tool call, which app made it, and from which IP address, so you can spot anything you don’t recognize.

## Data deletion when you cancel

Cancel from Settings and you won’t be charged again. Access runs to the end of the period you already paid for. When that period ends, every bank connection is revoked with the bank-data provider and deleted from our database.

Deleting your account goes further and happens immediately: bank connections, API keys, connector tokens, sessions, the call log, and your user record are all deleted. A short audit entry (time and reason of each bank removal) is kept for billing reconciliation. No financial data is kept, because none was stored.

## The demo

The demo is a shared sample account with made-up data. It can’t connect a real bank, change API keys, or be deleted, so nothing you do there touches real money or anyone’s real data.

## Report a security issue

Email [hello@greatwork.company](mailto:hello@greatwork.company) with details and steps to reproduce. BankBridge is built and run by Great Work LLC.

[Use your own bank](https://bankbridge.money/login)[Read the FAQ](https://bankbridge.money/faq)
