← Back to Help Center
Trust & Safety

Security & Privacy

How VaultEXP handles your bank connections, your money data and your documents — what we access, why we access it, where it is kept, and what we never touch.

Last reviewed 2 October 2026 · Applies to VaultEXP at securevaultexp.com

01 What VaultEXP is

A financial operating system for business owners and property investors.

VaultEXP brings a person's financial picture into one place: their businesses and properties, the bank accounts and cards behind them, invoices, bills and subscriptions, assets, liabilities and documents. It exists to let someone see and organise money they already have, across entities that would otherwise be scattered across separate logins.

Bank connections serve that purpose and no other. An account is connected so that VaultEXP can show its balance alongside everything else, and so that a bill or an invoice can record which account funded it. That is the whole of it.

The principle everything else follows from

We ask for the least access that makes the feature work, we say what it is for before asking, and we do not keep what we do not need. Where something is not possible, this page says so rather than leaving an impression that it is.

02 How a bank connection works

Your bank credentials never reach VaultEXP. They never pass through our servers, and they are never stored.

Bank connections are handled entirely by Stripe Financial Connections. When you choose to connect an account:

  • VaultEXP asks Stripe to begin a connection and receives a short-lived token that is designed to be public. Our secret key stays on our server and is never sent to your browser.
  • Stripe presents its own interface. You sign in to your bank with Stripe, not with us. Your username, password and any one-time code go from your browser to your bank through Stripe. VaultEXP cannot see them, and there is no point in our system where they could be intercepted, because they never travel through it.
  • Your bank returns a token to Stripe representing the account you chose. Stripe gives VaultEXP a reference to that token and the last four digits of the account number.
  • If your bank is not supported by the sign-in flow, Stripe falls back to verifying the account with two small deposits. Those details are entered into Stripe's own form, not ours.

The result is that VaultEXP holds a reference which can be used to show a balance and, with your instruction, to move money into your own VaultEXP wallet. It is not a copy of your account details and cannot be used anywhere else.

03 Exactly what we access, and why

One permission is requested. A second is optional and off unless you turn it on.

PermissionRequestedWhy
payment_method Always The minimum needed for an account to be usable at all: it is what lets a connected account be shown as a funding source and, on your instruction, be debited to top up your VaultEXP wallet.
balances Only if enabled Shows the real balance of the account instead of a figure you typed in. Read-only. Off by default; an operator must switch it on deliberately.
transactions Never VaultEXP does not read your bank transaction history.
ownership Never We do not request account-holder identity details from your bank.

What is stored about a connected account

  • The bank's name, and the account type it reported (for example "checking").
  • The last four digits only.
  • The Stripe reference for the account.
  • The balance, if that permission is enabled, with the time it was last confirmed — so you can always tell whether the figure you are looking at is current.
  • Which of your businesses, properties or personal wallet the account belongs to.
Worth being precise about

For a connected account, the fields that would hold a full account number and routing number are stored empty. Not masked, not encrypted — empty, because the number is never given to us in the first place.

04 What VaultEXP never does

Stated plainly, because a list of what a system will not do is usually more informative than a list of what it will.

  • We never see or store your bank login. It does not pass through our servers.
  • We never store your full account or routing number for a connected account. Stripe does not give it to us.
  • We never read your bank transaction history. The permission is not requested.
  • We never sell, rent or share your financial data with advertisers, data brokers or any third party for their own purposes.
  • We never move money without your instruction. There is no process that can initiate a transfer on its own.
  • We never use your bank data to train AI models. The AI features in VaultEXP read documents you upload and records you create, at your request, and nothing is used to train anybody's model.
  • We never let one business see another's accounts, or a business see your personal ones. See section 07.

05 Money movement

There is exactly one way money moves through VaultEXP, and you start it every time.

Topping up your wallet

You may move money from a connected account into your own VaultEXP wallet balance. You enter the amount and confirm it. The debit is made by Stripe, and a bank transfer takes three to five business days to clear. During that time the transaction is shown as pending and your balance is unchanged; it only moves when the bank confirms the money has actually arrived.

Before you confirm, VaultEXP tells you whether the payment is real or a test, and how long a bank transfer takes. Nothing is debited from a screen that does not say what it is about to do.

Recording bills and invoices

When a bill, subscription or invoice is marked as paid from a chosen account, VaultEXP records that payment and adjusts the balance it tracks for that account. This is bookkeeping. VaultEXP does not pay your electricity company, your landlord or any other third party, and cannot: the payment arrangement is the one you made with them directly.

If you tell VaultEXP that a bill is collected automatically by a vendor, it will record that payment on its due date so your books match what your bank has already done — without moving any money itself.

So there is no ambiguity

The only transfer VaultEXP can initiate is one you request, from your own connected account, into your own wallet. There is no mechanism for sending money to a third party, and no automated process that can start a debit on your behalf.

06 Storage and encryption

In transit

  • All traffic between your browser and VaultEXP is over HTTPS.
  • All traffic between VaultEXP and Stripe is over HTTPS with the server's certificate verified. Certificate verification is on, everywhere.
  • Every message Stripe sends us is checked against a signing secret before it is acted on. An unsigned or wrongly signed message is rejected.

At rest

  • Connected accounts hold no account number to protect — there is nothing stored that could be decrypted.
  • If you choose to type in an account by hand instead of connecting it (for tracking an account you do not want to link), those numbers are encrypted with AES-256-GCM — an authenticated cipher, so a tampered value is rejected rather than quietly decrypting to something else. The key is held in the server environment, never in the application's source.
  • Card numbers entered into the card vault are encrypted under a passphrase that you set and we do not hold.
  • Uploaded documents are stored outside the web root and are not reachable by URL. Files are served only through an authenticated request that checks you are entitled to that specific document.

Secrets

Stripe secret keys, encryption keys and signing secrets are held in the server environment, never in source control, and never sent to the browser. The browser only ever receives Stripe's publishable key and a short-lived token, both of which are designed to be public. Administrative tooling reports on key configuration without ever printing a key — only a fingerprint, enough to confirm a value changed and useless to anyone who intercepts it.

07 Who can see a connected account

Separation between areas is enforced by the server on every request, not by hiding things in the interface.

VaultEXP keeps money in separate areas: each business, each property, and your personal wallet. An account connected inside one business belongs to that business alone. It is not visible in your personal wallet, not visible in another business, and cannot be selected to pay another area's bills.

  • Every request that touches an entity's finances is checked against your access to that specific business or property. An identifier supplied by the browser is never trusted on its own.
  • A funding source is re-checked at the moment of payment, so a card or account cannot be used to pay something in an area it does not belong to.
  • Staff you invite see only what their role allows. Access is denied by default and granted deliberately.
  • Access to bank and wallet data is logged, so it can be reviewed.

08 Keeping and deleting your data

Disconnecting an account

You can disconnect a bank account at any time, from the same screen you connected it on. Disconnecting revokes the connection at Stripe. From that moment the account can no longer be charged, no balance is retrieved, and it stops counting toward any total.

The historical record of payments already made from that account is kept, and the account's name and last four digits remain attached to those past entries. This is deliberate: deleting it would leave your books with payments that came from nowhere. No live connection remains, and nothing further is retrieved.

Closing your account

You may request deletion of your VaultEXP account and its data. Bank connections are revoked at Stripe as part of that. Stripe retains its own records independently, under its own policy, as it is required to.

How long things are kept

  • Balances are replaced each time they are refreshed; older figures are not accumulated into a history.
  • Financial records you create — invoices, bills, expenses — are kept for as long as your account is open, because they are your books.
  • Security and access logs are retained so that access can be reviewed, and are not used for any other purpose.

10 Application security

  • Sessions. Cookies are HTTP-only and same-site, marked secure in production, and expire when the browser closes. Sessions time out after an hour of inactivity and twelve hours absolutely. Session identifiers supplied by a third party are rejected.
  • Sign-in. Passwords are stored hashed, never recoverable. One-time codes are supported for sign-in.
  • Request forgery. Every action that changes data requires a token tied to your session, so another site cannot act as you.
  • Injection. Database access uses parameterised statements throughout; values are never concatenated into queries.
  • Uploads. Stored outside the web root, with execution disabled in upload directories.
  • Payment endpoints. Session-authenticated and same-origin only. Removing a payment method verifies that it is yours before acting.
  • Duplicate charges. A wallet credit is applied exactly once per payment, enforced by a database constraint rather than by application logic alone, so a repeated notification from Stripe cannot credit twice.

11 Questions and reporting a problem

If something here is unclear, or you believe you have found a security issue, write to support@securevaultexp.com. Security reports are read first. Please include enough detail to reproduce the issue, and give us a reasonable opportunity to fix it before disclosing it publicly.

You may request a copy of your data, or its deletion, at the same address.

VaultEXP · securevaultexp.com · Bank connections provided by Stripe
© 2026 VaultEXP Security & Privacy · support@securevaultexp.com