Bank Connection Security
A transparent look at how Kantivo handles bank connectivity through Stripe Financial Connections, and exactly where every piece of data lives.
Your bank login details never pass through Kantivo. All authentication happens inside Stripe's independently secured widget, and your accounting data is stored securely in your own database.
How Bank Connection Works
Kantivo integrates with Stripe Financial Connections, the bank-data service from Stripe -- one of the world's largest and most trusted financial infrastructure companies -- to bridge the gap between your bank and your desktop accounting environment. The entire process is designed so that sensitive credentials remain outside of Kantivo at every stage:
Initiate the Connection
When you press "Link Bank with Stripe," a separate secured window from Stripe opens on your screen. This popup is hosted entirely by Stripe's infrastructure -- Kantivo has no access to its contents.
Authenticate with Your Bank
You sign into your financial institution directly within Stripe's encrypted interface. Your username and password travel exclusively between Stripe and your bank -- Kantivo cannot intercept or record them.
Receive a Read-Only Account Reference
Upon successful authentication, Stripe issues a limited-scope account reference to Kantivo. It permits transaction and balance retrieval only -- it cannot log into your account, authorize payments, or alter any banking information.
Pull Transactions into Your Local Database
Kantivo uses the reference to retrieve your transaction history through Stripe's API, then stores it securely in your database. Transactions are available immediately for reconciliation and reporting.
Where Is Data Stored?
| Data Type | Where It's Stored | Security |
|---|---|---|
| Bank Username & Password | These credentials are NEVER handled by Kantivo. They are submitted exclusively through Stripe's PCI-compliant widget and are invisible to our application. | Not Applicable |
| Stripe Account Reference | Persisted in a secure cloud database (Admin Panel). The credentials that actually reach your bank remain with Stripe -- only an identifier is stored on our side. | Held by Stripe |
| Bank Name & Account Names | Kept on your local machine within Kantivo's PostgreSQL database, used solely for labeling and display. | Non-sensitive metadata |
| Transaction History | Written to your local PostgreSQL database once you import. Your financial records never leave your computer. | Your local database |
Security Measures
-
🔐Your Login Details Stay Outside Kantivo Bank usernames and passwords are entered only within Stripe's PCI-compliant interface. At no point does Kantivo see, relay, or persist these credentials on your computer or elsewhere.
-
🔒Bank Tokens Never Leave Stripe The tokens that actually access your bank are custodied by Stripe, not by Kantivo. Our servers hold only an account identifier -- in the unlikely event of a database breach, your bank connection cannot be reconstructed from it.
-
🚫Strictly Read-Only The connection only authorizes Kantivo to read transaction and balance data through Stripe's API. It is impossible to use it to authenticate with your bank, move funds, or modify your accounts in any way.
-
📜Certified Financial Infrastructure All communications with Stripe travel over TLS encryption, and Stripe holds PCI Service Provider Level 1 certification -- the highest level in the payment industry -- along with SOC 1 and SOC 2 audits.
-
🔄Full Disconnect at Your Discretion You may sever the bank connection at any moment from within Kantivo. Doing so instantly invalidates the access token, preventing any further data retrieval.
Frequently Asked Questions
If you have additional security questions about bank connectivity, please contact us at support@kantivo.app