Security & Privacy
Your security is our top priority. Learn how we protect your financial data.
Your Data is Safe with Silvia
Silvia cannot make transactions on your behalf, or make changes to your banking accounts. You can revoke access at anytime. We do not store banking credentials on our servers. Your data will never be sold.
How we ensure our users are safe:
- Bank-level encryption: All data is encrypted in transit and at rest
- We will never sell your data
- We delete your data from our primary database when you delete your account
- Maintain an audit trail for all data access sessions internally
For your safety:
- When uploading tax documents (W-2s, 1099s, tax returns), we recommend redacting your Social Security number first — we don't need it to analyze your financial data
- Avoid sharing personal identification documents such as passports or national IDs
- Avoid storing highly sensitive information in Silvia that would be risky if compromised
- Sign up using your Google ID if you have 2FA set up for extra protection
What happens if Silvia's servers are breached?
We don't store your banking credentials, so they would be safe.
All your data is encrypted at rest — even if someone gained access to raw storage or backup files, they wouldn't be able to read it. Sensitive fields like names, emails, and access tokens are additionally encrypted at the application level with separate keys.

SOC 2 Type II Certified
Independently audited for security & data handling — the same standard trusted by banks and Fortune 500 companies.
Your data is secure at every step
Our Servers
All our databases and file storage have their content encrypted while stored and when they are backed up. This protects against unauthorized access, copying, transfer, or retrieval of your data from our servers.
Even if someone gained access to raw storage or backup files, they wouldn't be able to read it. Sensitive fields like names, emails, and access tokens are additionally encrypted at the application level with separate keys.
Our Team
Our support team does not have access to your personal data for debugging and customer support.
Decryption keys to access user data during routine maintenance is only by the CEO. Even their access is logged and audited.
Data is unmasked strictly on a need-to-know basis. Only team members who require access to improve or operate the system can unmask and access data.
When team members perform routine maintenance, debugging, or servicing of the system, they're required to provide a valid reason. We maintain an audit trail for all data access sessions.
Your Institutions
Bank Accounts: We use Plaid and other trusted providers to connect to your bank accounts. Your credentials are entered directly on your financial institution's login page — never on Silvia. We have read-only access, meaning we can't make any transactions on your behalf.
Crypto Accounts: For crypto exchanges like Coinbase, your accounts are connected via OAuth. Your account credentials are entered directly on Coinbase's official OAuth login page. Your credentials are never stored by Silvia. We have read-only access, meaning we can't make any transactions on your behalf.
Credential Storage: We never store your banking or crypto credentials on our servers.
Your Browser
We use HTTPS on all pages, and HSTS to ensure browsers only ever connect to us over a secure connection. This protects your data while it travels between our servers and your browser.
How does Silvia connect to my financial accounts?
- Bank Accounts: We use Plaid to connect to your bank accounts. Your banking credentials are never stored by Silvia. We have read-only access, meaning we can't make any transactions on your behalf.
- Crypto Accounts: For crypto exchanges like Coinbase, your accounts are connected via OAuth. Your account credentials are entered directly on Coinbase's official OAuth login page. Your credentials are never stored by Silvia. We have read-only access, meaning we can't make any transactions on your behalf.
- Credential Storage: We never store your banking or crypto credentials on our servers.
How is my data protected?
Your data is encrypted at rest and in transit. We do not have access to your bank credentials. Your data is isolated at the database level so only your authenticated session can access it.
At-rest encryption:
All our databases and file storage have their content encrypted while stored and when they're backed up. This protects against unauthorized access, copying, transfer, or retrieval of your data from our servers.
In-transit encryption:
We use HTTPS on all pages, and HSTS to ensure browsers only ever connect to us over a secure connection. This protects your data while it travels between our servers and your browser.
Does Silvia have access to my personal data?
- Our support team does not have access to your personal data for debugging and customer support.
- Our CEO holds the decryption keys to access user data during routine maintenance, debugging, and servicing of the system. Their access is logged and audited.
- Data is unmasked strictly on a need-to-know basis. Only team members who require access to improve or operate the system can unmask and access data.
- When team members perform routine maintenance, debugging, or servicing of the system, they're required to provide a valid reason. We maintain an audit trail for all data access sessions.
What happens if Silvia's servers are breached?
- We don't store your banking credentials, so they would be safe.
- All your data is encrypted at rest — even if someone gained access to raw storage or backup files, they wouldn't be able to read it. Sensitive fields like names, emails, and access tokens are additionally encrypted at the application level with separate keys.
Does Silvia sell my data?
Silvia NEVER sells your data to third parties or for advertising purposes.
What can I do to further protect my data?
- When uploading tax documents (W-2s, 1099s, tax returns), we recommend redacting your Social Security number first — we don't need it to analyze your financial data.
- Avoid sharing personal identification documents such as passports or national IDs.
- Sign up using your Google ID, especially if you already have Two-Factor Authentication (2FA) set up for your Google account.
- We have a strict 2FA policy for all team members to prevent hacking.
What happens when I delete my account?
When you delete your account, all your data is deleted from our primary database.
What if I find a security vulnerability?
If you believe you've found a security issue in our product or service, we encourage you to let us know at security@cfosilvia.com. We also are committed to engage with external security firms to review our application security.
Have More Questions?
We understand that Silvia handles your sensitive financial data, and protecting it is our highest priority. If you have more questions, please don't hesitate to contact us at security@cfosilvia.com. We're happy to help!