Security

Security at Fillfolio

How Fillfolio protects connected-account access, supports secure sign-in and gives you control over your portfolio data.

Your bank and brokerage passwords stay outside Fillfolio

Fillfolio uses Plaid and SnapTrade to connect supported financial accounts. You sign in through your institution or the provider's connection flow, not a Fillfolio form that collects your financial-account password.

Plaid

Plaid

Bank connections

Depending on your bank, you may sign in through your bank's website or app, or through Plaid's connection flow. Plaid does not share your bank login credentials with Fillfolio.

Where your bank supports OAuth, you review and authorize access directly with the bank. Before opening the connection flow, Fillfolio explains its bank-data use and requires your consent.

After authorization, Fillfolio retrieves supported account and balance information, including supported credit-card debt. Available data depends on your institution and authorization. Fillfolio does not retrieve bank transaction history.

Plaid's Trust Center lists SOC 2 Type II assurance and ISO 27001 and ISO 27701 certifications.

SnapTrade

SnapTrade

Brokerage and exchange connections

SnapTrade's connection portal handles institution sign-in and reconnection. It uses institution-hosted authorization where available; for other connections, SnapTrade may handle and store institution credentials encrypted. Fillfolio receives the connection result and supported data, not your institution's login password.

Fillfolio requests data-only access when creating or reconnecting a SnapTrade connection. Its tracking features do not place trades, transfer money or hold your assets. Available account information varies by institution.

SnapTrade documents encryption in transit and at rest and independent SOC 2 Type II assurance.

These assessments apply to the providers' services. They are not certifications or independent audits of Fillfolio.

What Fillfolio receives

Fillfolio receives the financial information you authorize and provider-issued access tokens or secrets used to retrieve supported data. Those connection credentials are sensitive, but they are different from your bank or brokerage login password. Fillfolio protects its stored connection credentials as described below.

Read-only financial connections

Fillfolio tracks your accounts without placing trades, transferring money or signing wallet transactions. Financial-institution sign-in happens through the connection provider or institution, not a Fillfolio password form.

Connection providers give Fillfolio access credentials for supported data retrieval. These are different from your bank or brokerage login credentials. Wallet tracking uses public addresses or supported extended public keys, never private keys or seed phrases.

Protecting your sign-in

You can enable account multi-factor authentication (MFA) on any plan. Connecting or reconnecting a bank requires additional verification with your enrolled authenticator or a recovery code, even if optional account MFA is off.

Server-side checks restrict access to the accounts and portfolios you own. Disabled or deleted Fillfolio accounts cannot continue using existing integration credentials to access portfolio data.

Protecting your connection tokens

Fillfolio uses HTTPS to protect information in transit. Stored Plaid access tokens and SnapTrade connection secrets are encrypted with AES-256-GCM before they are saved to the database.

These credentials let Fillfolio retrieve supported account data. This encryption claim applies to those stored connection credentials; it does not mean your entire portfolio is end-to-end encrypted. Fillfolio processes account data to provide tracking and synchronization.

You control connected access

Remove financial connections from Accounts & imports and revoke client authorizations in Settings. Revoking an integration stops its future authorized access. Account deletion revokes account access and starts billing and provider cleanup.

Provider cleanup can require retries, and some records remain for the purposes and periods described in the Privacy policy. Disconnecting or deleting Fillfolio does not erase downloads, spreadsheet copies or AI conversations you already shared with another service.

Privacy in everyday use

Privacy Mode hides sensitive values in Fillfolio's visible interface. Downloads and Google Sheets reports contain full financial values so you can calculate and analyze them. Review the export disclosure before sharing.

Application error monitoring is configured to filter sensitive context, including user details, request bodies and headers, and exception messages. Infrastructure services may still process request metadata and operational logs as described in the Privacy policy.

Reviewing and maintaining protections

Fillfolio uses internal security reviews and regression tests to check access boundaries and fixes. Documented recovery exercises check backup restoration and release rollback in isolated environments.

Fillfolio has completed Plaid's security questionnaire and OAuth registration steps for its bank integration. These onboarding steps and internal reviews are not an independent security audit or certification of Fillfolio, or a guarantee that an internet service is free from risk.

Google Sheets and AI access

Google Sheets

Google Sheets synchronization is manual and one-way, from Fillfolio to the current spreadsheet. Reports contain full financial values even when Privacy Mode is on. Review who can access the spreadsheet before syncing or sharing it.

Google Sheets access and exports

AI assistants and MCP

AI access requires its own sign-in and approval and is read-only. Installing the Sheets add-on does not authorize an AI assistant. You can revoke an assistant's access in Settings.

Information returned to an external AI assistant is also subject to that service's privacy and retention policies. Revocation stops future retrieval; it does not retract information already received or erase existing conversations.

How authenticated AI access works

Your security questions

Does Fillfolio receive my bank or brokerage password?

No. Institution sign-in happens through your bank, brokerage or connection provider. Depending on the connection, the provider may handle and store institution credentials; they are not shared with Fillfolio. Fillfolio receives authorized account data and separate provider connection credentials for supported tracking features.

Why can bank connection permissions be broader than the balances I see?

Plaid or your institution may request broader permissions to establish and maintain a recurring connection. Fillfolio limits its provider calls to connection and institution metadata, account metadata and balances, connection updates, and revocation. It does not call bank transaction-history, Auth, Identity, account-number or Signal endpoints.

How is a connection token different from my login?

Your bank or brokerage login authenticates you with that institution or its connection provider. A provider connection token or secret lets Fillfolio retrieve the supported data you authorized. Your Fillfolio login is a separate account for opening Fillfolio itself, with its own sign-in and MFA controls. Protect all three; a connection token is sensitive even though it is not your bank password.

Can Fillfolio trade or move my money?

No. Fillfolio provides read-only tracking and does not place orders, transfer funds, take custody or sign wallet transactions. Connecting an institution authorizes the supported data access shown in its consent flow. Wallet tracking uses public addresses or supported extended public keys, never private keys or seed phrases.

How are my connection credentials encrypted?

Fillfolio uses HTTPS for information in transit and AES-256-GCM to encrypt stored Plaid access tokens and SnapTrade connection secrets before database storage. These are provider access credentials, not your financial-institution login passwords. This does not mean all portfolio data is end-to-end encrypted: Fillfolio processes account data to provide the service.

How do I disconnect accounts or revoke integration access?

Remove financial connections from Accounts & imports and manage client authorizations in Settings. Sheets and the browser extension also have Disconnect controls. Revocation stops future authorized access; reconnecting requires a new authorization. It does not erase files, spreadsheet cells or chat responses you already exported to another service.

Does Privacy Mode hide values in downloads and Google Sheets?

No. Privacy Mode hides values in Fillfolio's visible interface; downloads and Google Sheets reports contain full financial values for calculations and analysis. Review the export disclosure and share files carefully. Disconnecting a client does not remove existing exports, spreadsheet copies or version history.

How do I delete my Fillfolio account?

Open Settings and use the account-management deletion flow, then review and complete its confirmation. Deletion revokes account access and starts billing and connection cleanup. Some records may be retained where required by the Privacy policy or law. Deleting Fillfolio does not delete your Google account or copies you previously exported. Contact support if you cannot access the account.

View all FAQs

Report a security concern

Describe what you observed and how to reproduce it. Do not include passwords, recovery codes, access tokens or financial credentials.