Security & Trust
Astra asks for something serious: a view of your whole financial life. Here's exactly how we protect it.
Account linking runs through Plaid, the same infrastructure used by leading financial apps. You authenticate directly with your institution. Your banking username and password never touch Astra's servers, and we couldn't store them if we wanted to.
Passwords are hashed with argon2 (never stored in plain text), sessions expire automatically, sign-in attempts are rate-limited against brute force, and every request is protected against cross-site request forgery.
Astra is subscription-funded. We do not sell personal information, we do not share it for advertising, and we contractually restrict our service providers from using your data for their own purposes.
Linked accounts give Astra visibility, not control. Anything beyond analysis (a submission, a switch, a payment) happens only with your explicit, per-action authorization, which you can revoke at any time.
Security-relevant events are logged and auditable: sign-ins, data pulls, authorizations, and legal acceptances each carry a timestamp and version. You can request a copy of your data, or deletion, at any time.
If a breach ever affects your personal information, we will notify you as required by law, plainly and promptly. Questions or concerns reach a person at [email protected].
The fine print lives in our Privacy Policy and Terms of Service. Found a vulnerability? Email [email protected] and we'll take it seriously.