Security & Trust

Built to be trusted with your money.

Astra asks for something serious: a view of your whole financial life. Here's exactly how we protect it.

We never see your bank credentials

Account linking runs through Plaid, the same infrastructure used by leading financial apps. You authenticate directly with your institution. Your banking username and password never touch Astra's servers, and we couldn't store them if we wanted to.

Hardened sign-in

Passwords are hashed with argon2 (never stored in plain text), sessions expire automatically, sign-in attempts are rate-limited against brute force, and every request is protected against cross-site request forgery.

Your data is not the product

Astra is subscription-funded. We do not sell personal information, we do not share it for advertising, and we contractually restrict our service providers from using your data for their own purposes.

Read-only by default

Linked accounts give Astra visibility, not control. Anything beyond analysis (a submission, a switch, a payment) happens only with your explicit, per-action authorization, which you can revoke at any time.

Everything on the record

Security-relevant events are logged and auditable: sign-ins, data pulls, authorizations, and legal acceptances each carry a timestamp and version. You can request a copy of your data, or deletion, at any time.

Straight answers when it matters

If a breach ever affects your personal information, we will notify you as required by law, plainly and promptly. Questions or concerns reach a person at [email protected].

The fine print lives in our Privacy Policy and Terms of Service. Found a vulnerability? Email [email protected] and we'll take it seriously.