Security at Atlas Ledger

Last Updated: October 9, 2026

Short version: you connect your bank through Plaid (or Teller for some banks), so we never see your bank password. Atlas Ledger reads your financial data and cannot move money. The secrets that matter most are encrypted in our database, your sign-in lives in cookies that page scripts cannot read, and you can see and sign out your devices, download your data, or delete your account at any time. We are a small company, so this page also lists what we don't do yet.

1. Bank connections

2. Signing in

3. How your data is protected

4. Your data, your choice

5. How we run the service

6. What we don't do yet

We would rather tell you than have you assume:

7. Reporting a security problem

If you think you've found a security vulnerability in Atlas Ledger, please email [email protected] with "Security" in the subject. Tell us what you found, the steps to reproduce it, and what an attacker could do with it. Our contact details are also published in security.txt.

When testing, please:

Safe harbor: if you make a good-faith effort to follow these guidelines, we will not take or support legal action against you for your research, and we will work with you to understand and fix the problem.

What to expect: we aim to reply within a few business days and will keep you updated while we work on a fix. We don't pay bounties, but with your permission we'll gladly thank you by name. Problems in services we rely on (such as Plaid, Stripe, Google, or Apple) should go to those companies directly.

← Back to Home