← Back to KeepUp

Security at KeepUp

Last Updated: July 9, 2026

KeepUp shows you your complete financial picture. Because that picture is sensitive, we designed the product so that the worst case is always limited: your money never moves, and your bank logins never touch our servers. This page explains, in plain English, how that works. The legally authoritative detail lives in our Privacy Policy.

We're not a bank – and that's the point

KeepUp never holds, moves, or manages your money. There is no transfer button, no payment rail, no trading integration – not hidden, not disabled: it doesn't exist. Every account connection is read-only. If a KeepUp account were ever compromised, the attacker could not move a cent, because KeepUp itself can't.

How account connections work

Bank and brokerage connections run through Plaid – the same connectivity infrastructure used by Venmo and American Express. When you link an account:

  • You sign in on your bank's own page or app (typically via OAuth). Your username and password go to your bank, never to KeepUp – we have no way to see or store them.
  • Plaid gives KeepUp a read-only token that can retrieve balances, holdings, and transactions – and nothing else. It cannot initiate transfers or change anything at your institution.
  • You can disconnect any account in KeepUp at any time, which revokes the token at Plaid. You can also review and revoke connections directly with Plaid at my.plaid.com.

Plaid publishes its own security practices, certifications, and sub-processor list at security.plaid.com.

Crypto exchanges – Coinbase, Binance, and Kraken, for users in the United States for now – connect through SnapTrade, on the same read-only terms:

  • You authorize the connection inside SnapTrade's secure window, either by signing in at the exchange (Coinbase) or by pasting a read-only API key you create at the exchange (Binance, Kraken). Those credentials go to SnapTrade, never to KeepUp – we have no way to see or store them.
  • The connection can retrieve balances, holdings, and transaction history – and nothing else. It cannot trade, move, or withdraw anything.
  • KeepUp identifies you to SnapTrade with a pseudonymous ID only – no name, no email.
  • Disconnecting an exchange in KeepUp revokes the authorization at SnapTrade. You can also revoke it at the exchange itself, by removing the connected app or deleting the API key.

Passkeys guard every new connection

Linking a financial institution requires a passkey – a phishing-resistant check (Touch ID, Face ID, Windows Hello, or a hardware security key) under the FIDO2 / WebAuthn standard, completed moments before the link is created. No passkey enrolled yet? We walk you through it before your first connection. A stolen password or a hijacked session is not enough to connect a bank or expose new accounts on a KeepUp account – few financial apps, including most incumbents, enforce this.

Encryption in transit and at rest

  • All traffic to and from KeepUp is encrypted with TLS (HTTPS).
  • Our databases are encrypted at rest by our hosting provider.
  • Plaid access tokens and SnapTrade connection secrets get a second layer: they are encrypted at the application level with authenticated encryption (AES with HMAC, via Fernet) before they ever reach the database, are never returned by our API, and are never written to logs.

What we never store

  • Your bank or exchange credentials. They are entered at your institution or with our connection provider, never on KeepUp.
  • Full account or card numbers. We receive at most a display mask (like ••••1234) so you can tell accounts apart.
  • The ability to move money. Not stored, because it was never granted.

Your data: export it or erase it, instantly

You can download your complete data set as machine-readable JSON at any time ("Download my data" under Account Settings → Your Data). And you can delete your account at any time: your portfolio, snapshots, and connections are removed from our active systems immediately, with Plaid tokens and SnapTrade authorizations revoked first. Hosting-provider backups age out within 30 days. Details in Privacy Policy Section 10.

Found a vulnerability?

We want to hear about it, and we'll respond quickly. Email [email protected] with enough detail to reproduce the issue. Good-faith security research is welcome; we won't pursue action against researchers who report responsibly and give us reasonable time to fix. Our machine-readable contact record lives at /.well-known/security.txt.