🔒 BANK-LEVEL SECURITY

Your financial data, locked down.

We built Clarity Books with security as a first principle, not an afterthought. Here is exactly how your data is protected, in plain language.

AES-256
Encrypted at rest
TLS 1.2+
Encrypted in transit
Read-only
Bank access
SOC 2
Certified infra
How we protect you

Nine layers of protection

🔒

256-bit AES Encryption at Rest

Your database and file storage are encrypted with AES-256 at the infrastructure layer by our provider (Supabase), the same standard used by banks and the U.S. government. On top of that, we encrypt your Plaid bank-connection token with AES-256-GCM in our own application before it is stored.

🛡️

Modern TLS in Transit

All data traveling between your browser, our servers, and third-party providers is encrypted in transit with modern TLS (1.2 or higher). Our hosting and database providers negotiate current TLS versions and disable obsolete ones.

👁️

Read-Only Bank Access

When you connect a bank account via Plaid, we receive a read-only token. We can see your transactions and balances. We cannot initiate transfers, move money, or interact with your account in any way.

🏗️

SOC 2 Type II Infrastructure

Our database and authentication run on Supabase, which maintains a SOC 2 Type II certification, meaning an independent auditor has verified their security controls annually. Your code and assets are hosted on Vercel, which is also SOC 2 certified.

🔑

Role-Based Access Control

Internally, only the admin user you authorize can view your books. Access roles are encoded into your session JWT and verified on every request. No request can access another user's data, even with a valid session token.

🧱

Row-Level Security (RLS)

Our database enforces row-level security policies at the Postgres layer, not just in application code. Even if a bug slipped through in our API, the database itself would reject unauthorized queries.

🏦

No Stored Banking Credentials

We never see or store your bank username or password. Plaid handles authentication directly with your financial institution using OAuth where available. Your credentials never touch our systems.

📱

Optional Two-Factor Authentication

You can turn on two-factor authentication (TOTP) from your account settings on the web. Once enabled, signing in requires a one-time code from your authenticator app (Google Authenticator, Authy, 1Password, etc.) in addition to your password, an extra lock you control.

🗑️

Right to Delete

Close your account and your records (transactions, invoices, AI-learned rules, and the receipt and document files you uploaded) are deleted immediately and irreversibly. You can trigger this yourself from Settings: no phone call, no waiting. Encrypted infrastructure backups roll off within about 30 days.

Bank connections

Powered by Plaid, the industry standard

We use Plaid to connect to your financial institutions. Plaid is trusted by Venmo, Robinhood, and thousands of fintechs. They authenticate you directly with your bank using OAuth wherever possible. Your username and password never pass through our servers.

The access token we receive is scoped to transactions and balances only. It cannot be used to initiate payments, view full account numbers, or change any account settings.

What Plaid shares with us
Transaction date, amount, and description
Account balance (current & available)
Institution name and account type
Your bank username or password
Full account or routing numbers
Ability to initiate transfers
Access to other accounts at the same institution
AI & your data

What the AI sees, and what it doesn't

For categorizing transactions we send only a few fields. When you upload a document for the AI to read, the file is sent so Claude can read it. See the note below.

✅ Sent for categorization
Vendor name (e.g. "Starbucks")
Transaction amount
Transaction date
Memo / description field
Your business type
Previously learned category rules
❌ Never sent to AI
Your account login or password
Bank login credentials
Full bank account or routing numbers
Any other customer's data
Reading documents you upload: when you send a receipt, bank or credit-card statement, or CSV for the AI to read, the file is sent to Claude so it can read the text. Image and PDF files are sent in full; for very large CSV files, only the first portion is sent. These files are not redacted, so any names, addresses, or tax IDs printed on them are included. Under our agreement with Anthropic, data sent through its API is not used to train its models.
FAQ

Common security questions

Can Clarity Books move my money?
No. We use Plaid in read-only mode. The token we receive is scoped to transaction and balance data only. There is no technical path by which our application can initiate a transfer or interact with your bank account.
Does the AI see my account numbers?
No, we never send your full bank account or routing numbers, bank login, or password to the AI. For categorization we send only the vendor name, amount, memo, and date. One thing to know: when you upload a document for the AI to read (a receipt, bank statement, or CSV), the file is sent to Claude so it can read it, including anything printed on it (images and PDFs in full; very large CSVs are truncated). Under our agreement with Anthropic, this data is not used to train its models.
Who inside Clarity Books can see my data?
Only the owner (Brayden Callahan). There is no support team with shared database access. Administrative access is restricted to the owner and protected by our infrastructure providers' account security.
What happens if there's a breach?
We will notify you by email within 72 hours of discovering any unauthorized access to your data. We will describe what was accessed, what we're doing about it, and what steps you should take.
Is my data shared with third parties for advertising?
Never. Your financial data is used solely to provide the bookkeeping service. We do not sell data, build advertising profiles, or share information with data brokers.
Where is my data stored geographically?
Your data is stored in the United States by our infrastructure providers (Supabase for the database and files, Vercel for hosting). We run in US regions and do not transfer your bookkeeping data outside the United States.

Have a security question?

If you discover a potential vulnerability or have a question about how we handle your data, reach out directly. We take every report seriously.

brayden@claritybooksai.com
HomePrivacyTerms