Security
Read-only access, narrow boundaries.
Bank access is limited to reading account information. The controls below describe how that access is bounded and how your data is protected.
Last updated: 21 August 2026What bank access can do
SubCut requests read-only account-information access through our open banking provider. SubCut is not FCA authorised and cannot move money, make payments, withdraw funds or cancel a subscription automatically.
Authentication happens with the bank/provider. SubCut never receives a bank password. Disconnecting a bank from your dashboard withdraws that consent and removes the data it provided.
How account data is protected
- Provider access and refresh tokens use AES-256-GCM before database storage.
- Token tables have zero client policies and zero client grants.
- Readable financial tables are tenant-scoped and client SELECT-only.
- Composite database constraints reject cross-user parent relationships.
- Provider payloads are normalized in memory and never persisted.
- Application logs exclude PII, tokens, statement descriptions and payloads.
TLS protects data in transit. No system is risk-free, which is why you can export or delete your data at any time.
Control and recovery
The dashboard exports account data as JSON or transaction CSV and can synchronously delete the account after recent authentication and confirmation. Disconnecting one source removes its rows and rebuilds derived results from any sources left.
Sync writes are idempotent, token refresh uses compare-and-set, and the database allows one running sync per connection. Optional AI failures fall back without aborting the classification or cancellation flow.
Reporting a security issue
If you believe you have found a vulnerability, email hello@subcut.co.uk with enough detail to reproduce it. We investigate every report we receive.
Please do not test against other people's accounts or data. We will not pursue action against good-faith research that respects that boundary.