Back to blog

How Silvia Protects Your Financial Data

Watercolor blog cover for How Silvia Protects Your Financial Data with the Silvia wordmark and neutral paint accents

Handing an app the login to your bank feels like a big step. Here's what actually happens when you connect an account to Silvia, how your data is protected once it's there, and the safeguards behind each part of the system.

You handed Silvia your entire financial life. Here's exactly what we do with that access, what we don't, and every claim you can verify yourself.

Five things Silvia can't do

Silvia can't see your credentials. When you connect a bank, you log in on your bank's own screen through Plaid. Your username and password never touch our servers. This is the same pattern Venmo, Robinhood, Cash App, and other finance apps rely on. If someone breached Silvia tomorrow, the one thing they'd walk away without is anything that would let them into your accounts.

Silvia can't move your money. Every connection is read-only. Not "read-only unless a support agent needs otherwise." Read-only, always. Plaid, SnapTrade, and other providers all offer money-movement products, but we deliberately left them disabled. The tokens Silvia holds carry read-only permissions, so a transfer request from our servers would be rejected by the provider before it ever reached your bank.

Silvia has no password to lose. We use passwordless authentication. Every login sends a one-time code to your email address. There's no shared password stored anywhere in our database that a breach could expose. The credential you'd worry about losing is one we never asked you to create.

Silvia can't unlock your sensitive data, even from inside the database. Modern databases already encrypt everything on disk. That's table stakes. On top of that, Silvia encrypts your name, email, and every stored access token a second time before writing them, using separate keys the database itself doesn't have. If someone got full read access to our database tomorrow, they'd find a spreadsheet of transactions with no way to tie them back to a real person, and no way to log into any of your accounts.

No one at Silvia can browse your data on a whim. Access to production data is restricted, logged, and requires a documented business reason. Every access is tied to a specific action on a specific ticket, and every access leaves an audit trail. This is one of the controls we're audited against under SOC 2.

What actually happens when you connect a bank

This is the moment most people hesitate. Handing an app the login to your primary checking account feels like a bigger step than every other step combined. Here's exactly what happens under the hood, so you can decide with the full picture.

We don't build the bank connection ourselves. We use Plaid. Plaid is the infrastructure layer that connects thousands of finance apps to thousands of banks. Plaid is a US-registered financial-services company, SOC 2 Type II certified, has direct partnership integrations with JPMorgan Chase, Wells Fargo, Bank of America, Capital One, and hundreds of other institutions, and is used by tens of millions of Americans every day. If you've ever linked a bank account to a modern finance app, you've almost certainly used Plaid without noticing - it's the same pipe behind Venmo, Robinhood, Coinbase, Cash App, Wise, Chime, SoFi, and most finance apps you've heard of. Think of it as Stripe for account connectivity: boring, ubiquitous infrastructure that most of the industry runs on.

Your bank login happens on your bank's own screen, brokered by Plaid. When you click "Connect a bank" in Silvia, a Plaid-hosted window opens over the app. You choose your bank, and from that point on you're logging in through either your bank's own OAuth page (for major banks like Chase, Wells, BofA, Capital One, and dozens more) or a Plaid-rendered page that submits credentials directly to your bank. In every case, your username and password go straight to your bank. They never come anywhere near Silvia's servers. We couldn't see them if we wanted to.

What Silvia gets back is a read-only token. After you finish the login, Silvia receives a limited-scope access token from Plaid. That token can pull account names, balances, and transaction history. It cannot log into your bank. It cannot see or reset your password. It cannot initiate a transfer. It cannot make any change to your account. If we lost that token tomorrow, the worst-case outcome is that we can't refresh your data until you reconnect. There is no path from "token stolen" to "money moved" because the token doesn't have that capability.

Disconnecting is instant, and you can do it from three different places.

  1. In Silvia, from the account settings. Disconnect a bank and the token is revoked in Plaid's system within seconds.
  2. In your bank's own app or website, in the "connected apps" or "third-party access" section. Revoke Plaid's access there, and it severs Silvia's connection too.
  3. On Plaid's dashboard at my.plaid.com, where you can see every app you've ever connected through Plaid and revoke any of them, any time, without going through us or your bank.

For institutions where Plaid isn't the strongest option, Silvia routes you through other aggregators. Today that's SnapTrade for certain brokerages (Fidelity, Schwab, Interactive Brokers, and others), with additional providers like MX coming next. We use a mix so you get the most reliable connection to whichever institution you're linking. Every aggregator we use follows the exact same read-only pattern as Plaid: credentials never touch our servers, and none of the tokens we receive carry any trading or transfer permission. Revocable at any time.

The pattern across all three is the same: you log in on the institution's own screen, and Silvia gets back a token that can look but can't touch.

Three things you can verify without taking our word for it

  • We're SOC 2 Type II certified. Independently audited by a licensed CPA firm and monitored continuously through Vanta, the compliance platform used by Notion, Vercel, and thousands of other serious SaaS companies. You can request the attestation letter from our public trust center at trust.cfosilvia.com. Most of our competitors either publish a badge without a link or aren't certified at all.
  • You can see the security controls that hold us accountable. Our trust center at trust.cfosilvia.com publishes the specific controls we're audited against under SOC 2, grouped into infrastructure security, organizational security, product security, internal procedures, and data and privacy. Each control has a current status. Most personal-finance apps refuse to publish anything at this level of granularity.
  • Our AI is documented in public. We publish a written AI transparency statement covering what our models do, what data trains them, what third parties we use, and what your rights are. We wrote it against the EU AI Act's Article 50 disclosure requirements. For an AI-powered product this deep in your financial life, we think that level of disclosure is essential.

What happens if…

A more direct way to think about everything above: what can actually go wrong, and what does it look like when it does?

What happens if someone tries to log into my Silvia account? Silvia doesn't use passwords. To sign in, you enter your email address, and Silvia sends a one-time code to that email. That code is the only way in, which means the single door someone would need to walk through to reach your Silvia account is your email inbox. Your email account is effectively the key to Silvia. Turn on strong two-factor authentication on your email (ideally an authenticator app or hardware key, not SMS), and the door is closed. For an extra layer on top, you can turn on Silvia's own in-app 2FA (authenticator or SMS) in Settings, which we then require in addition to the email code.

What happens if my phone gets stolen? The bank, brokerage, and crypto exchange apps on your phone each have their own login and biometric protection, so those aren't Silvia's line of defense to worry about. For Silvia itself: if the thief can get past your phone lock and open your email inbox, they could request a Silvia login code and use it. This is exactly why the optional in-app 2FA layer in Silvia's Settings is worth turning on. With that on, a stolen phone alone isn't enough to get into Silvia. If it happens without that layer set up, the fastest move is to sign your email account out of the phone from any other device you control, which severs the phone's ability to receive any new login codes.

What happens if Silvia itself gets hacked? Worst case, an attacker gets full read access to our production database. They would see transactions with no way to link them to a real person, because names, emails, and access tokens are all encrypted a second time with keys stored outside the database. They still can't move money from your accounts because we don't have that ability. They still can't log into your banks because we don't have your bank credentials. The damage stops with visibility into transactions that can't be tied back to any specific person.

What happens if I lose access to my email or my 2FA device? If your email is what you've lost access to, that's the first place to fix. Since login codes go to email, restoring your email restores your Silvia access with no extra Silvia-side steps. If you've turned on Silvia's optional in-app 2FA and lost the device it lives on, standard account recovery through identity verification kicks in. We don't skip the second factor during recovery; we re-establish it after we've confirmed you're you.

What we recommend you never do inside Silvia (or any finance app)

None of the advice below is unique to Silvia. It's the same guidance any security professional would give you about any app that lets you upload documents, including our competitors. Most of them don't tell you this out loud, so we will.

  • Don't upload documents with your Social Security number visible. Not to Silvia, not to any finance app. SSNs are the one identifier most Americans have that literally cannot be rotated. You can change a credit card in a day, but not your SSN. So the fewer copies of it exist across all the apps you use, the safer you are. Silvia doesn't need it to analyze your W-2 or tax return. Redact the number before you upload, and you shrink your exposure across every service that ever touches that document.
  • Don't upload passport or driver's-license photos unless a specific feature explicitly requires them. Same reason: they contain more identifying information than any legitimate use case here needs.
  • Turn on two-factor authentication on your email account first, then everywhere else that matters. Silvia doesn't have a password. We send a one-time login code to your email, which makes your email account the actual front door to Silvia. Turn on strong 2FA there first (ideally an authenticator app or hardware key, not SMS), then do the same for your banking, brokerage, and crypto apps. That single move is the highest-ROI thing you can do for your entire digital financial life. Once your email is locked down, turn on Silvia's own optional in-app 2FA in Settings for a second layer on top of the email code.
  • Do rotate a bank connection if your bank has a public breach. Disconnect and reconnect in Silvia. It takes 30 seconds and severs any stored access token, forcing a fresh handshake with your bank.

AI and your money: the honest version

Silvia's AI has to read your financial data. That's the entire product. If your AI can't see your accounts, it can't tell you whether you can afford a house, whether your ETF allocations overlap, or whether you're paying tax on the same dollar twice. Every AI-powered personal finance product on the market works this way.

What we do instead, and what we've written down publicly: we contractually prohibit our model providers from training on your data, you can opt out of our own model improvement at any time by emailing privacy@cfosilvia.com, we minimize the data sent to the model on every request, and we log which model was used for which request. If you'd rather your financial life not touch an AI system at any level, Silvia is honestly not the right product for you. If you're comfortable with the tradeoff (a smart assistant in exchange for machine-readable data), we've built the guardrails around it as tightly as any AI product of this kind can.

A note from the person who built this

I built Silvia because I got tired of financial apps that treated my data like inventory to sell to the highest bidder. Every design decision on the security side comes from the same instinct: do the thing I'd want done with my own money.

We take security seriously because you handed us something serious. If you find a way to break Silvia's security, or you think we've missed something on this page, my team reads every message at security@cfosilvia.com.

Thanks for trusting us with this. We work hard to deserve it.

Share this article

Your money deserves superintelligence.

Free forever. No card required. Give Silvia five minutes and see what an AI CFO trained on your money actually knows.