How VaultEXP handles your bank connections, your money data and your documents — what we access, why we access it, where it is kept, and what we never touch.
A financial operating system for business owners and property investors.
VaultEXP brings a person's financial picture into one place: their businesses and properties, the bank accounts and cards behind them, invoices, bills and subscriptions, assets, liabilities and documents. It exists to let someone see and organise money they already have, across entities that would otherwise be scattered across separate logins.
Bank connections serve that purpose and no other. An account is connected so that VaultEXP can show its balance alongside everything else, and so that a bill or an invoice can record which account funded it. That is the whole of it.
We ask for the least access that makes the feature work, we say what it is for before asking, and we do not keep what we do not need. Where something is not possible, this page says so rather than leaving an impression that it is.
Your bank credentials never reach VaultEXP. They never pass through our servers, and they are never stored.
Bank connections are handled entirely by Stripe Financial Connections. When you choose to connect an account:
The result is that VaultEXP holds a reference which can be used to show a balance and, with your instruction, to move money into your own VaultEXP wallet. It is not a copy of your account details and cannot be used anywhere else.
One permission is requested. A second is optional and off unless you turn it on.
| Permission | Requested | Why |
|---|---|---|
payment_method |
Always | The minimum needed for an account to be usable at all: it is what lets a connected account be shown as a funding source and, on your instruction, be debited to top up your VaultEXP wallet. |
balances |
Only if enabled | Shows the real balance of the account instead of a figure you typed in. Read-only. Off by default; an operator must switch it on deliberately. |
transactions |
Never | VaultEXP does not read your bank transaction history. |
ownership |
Never | We do not request account-holder identity details from your bank. |
For a connected account, the fields that would hold a full account number and routing number are stored empty. Not masked, not encrypted — empty, because the number is never given to us in the first place.
Stated plainly, because a list of what a system will not do is usually more informative than a list of what it will.
There is exactly one way money moves through VaultEXP, and you start it every time.
You may move money from a connected account into your own VaultEXP wallet balance. You enter the amount and confirm it. The debit is made by Stripe, and a bank transfer takes three to five business days to clear. During that time the transaction is shown as pending and your balance is unchanged; it only moves when the bank confirms the money has actually arrived.
Before you confirm, VaultEXP tells you whether the payment is real or a test, and how long a bank transfer takes. Nothing is debited from a screen that does not say what it is about to do.
When a bill, subscription or invoice is marked as paid from a chosen account, VaultEXP records that payment and adjusts the balance it tracks for that account. This is bookkeeping. VaultEXP does not pay your electricity company, your landlord or any other third party, and cannot: the payment arrangement is the one you made with them directly.
If you tell VaultEXP that a bill is collected automatically by a vendor, it will record that payment on its due date so your books match what your bank has already done — without moving any money itself.
The only transfer VaultEXP can initiate is one you request, from your own connected account, into your own wallet. There is no mechanism for sending money to a third party, and no automated process that can start a debit on your behalf.
Stripe secret keys, encryption keys and signing secrets are held in the server environment, never in source control, and never sent to the browser. The browser only ever receives Stripe's publishable key and a short-lived token, both of which are designed to be public. Administrative tooling reports on key configuration without ever printing a key — only a fingerprint, enough to confirm a value changed and useless to anyone who intercepts it.
Separation between areas is enforced by the server on every request, not by hiding things in the interface.
VaultEXP keeps money in separate areas: each business, each property, and your personal wallet. An account connected inside one business belongs to that business alone. It is not visible in your personal wallet, not visible in another business, and cannot be selected to pay another area's bills.
You can disconnect a bank account at any time, from the same screen you connected it on. Disconnecting revokes the connection at Stripe. From that moment the account can no longer be charged, no balance is retrieved, and it stops counting toward any total.
The historical record of payments already made from that account is kept, and the account's name and last four digits remain attached to those past entries. This is deliberate: deleting it would leave your books with payments that came from nowhere. No live connection remains, and nothing further is retrieved.
You may request deletion of your VaultEXP account and its data. Bank connections are revoked at Stripe as part of that. Stripe retains its own records independently, under its own policy, as it is required to.
Nothing is connected without a deliberate action, and the screen that asks says what will happen.
Every place you can connect an account, you can instead type one in for tracking only. An account recorded that way is never charged and is never connected to anything — it exists so your books can be complete without granting access you would rather not grant.
If something here is unclear, or you believe you have found a security issue, write to support@securevaultexp.com. Security reports are read first. Please include enough detail to reproduce the issue, and give us a reasonable opportunity to fix it before disclosing it publicly.
You may request a copy of your data, or its deletion, at the same address.