Skip to main content

Read-only by design

Last updated

Your money is yours. We just read the receipts.

Shelter cannot move your money. It cannot store your bank password. It cannot sell your data. Here are the receipts.

The short list

What Shelter cannot do

No transfers. No password. No card.

These are absences, not promises. There is no endpoint in the codebase that can move your money, store a bank password, or process a card.

  • Move money out of your bankNot built
  • See or store your bank passwordNever sees it
  • Store your card numberStripe holds it
  • Sell your financial dataNot the business model

Read the code

How it works

Four receipts, each pointing at the file that ships it.

  1. How we connect

    Plaid read-only access token

    Shelter opens a Plaid Link flow. Plaid handles the bank login. Plaid returns a read-only access token. Shelter never sees your bank password.

    Source file: convex/plaid.ts

  2. How we store the token

    AES-256-GCM, random IV, auth tag

    Before the Plaid access token is written to the database, it is encrypted with AES-256-GCM. A fresh random IV is generated per token and the auth tag is stored alongside the ciphertext.

    Source file: convex/utils/encryption.ts

  3. How you sign in

    Clerk-issued JWT

    Authentication is handled by Clerk. Shelter validates a Clerk-issued JWT on every request. Your password is held by Clerk; Shelter never stores it.

    Source file: convex/auth.config.ts

  4. How payment works

    Stripe-hosted checkout

    Card details are entered into Stripe, not Shelter. Shelter only stores a Stripe customer id and subscription status. Your card number never reaches our servers.

    Source file: convex/subscriptionService.ts

How we serve the page

TLS plus a real header set

shelter.money is served over TLS, terminated by Railway. The web app sets the following response headers on every route:

Content-Security-Policy is enforced on every route alongside HSTS, frame restrictions, MIME sniffing protection, a strict referrer policy, and a permissions policy.

Source file: web/next.config.js

  • Strict-Transport-Security
    max-age=31536000; includeSubDomains; preload
  • X-Frame-Options
    SAMEORIGIN
  • X-Content-Type-Options
    nosniff
  • Referrer-Policy
    strict-origin-when-cross-origin
  • Permissions-Policy
    camera=(), microphone=(), geolocation=()

Step by step

How bank linking actually works

  1. You tap "Link bank" inside Shelter.

  2. Plaid takes over. You enter your bank credentials with Plaid, not Shelter.

  3. Plaid returns a read-only access token. Shelter encrypts it before storing it.

  4. Shelter reads balances and transactions. There is no write path.

For Plaid's own security practices, read Plaid's trust and safety resources.

  • Read-only Plaid connection
  • Shelter cannot move money
  • No ads. No selling your financial data.

The same three commitments that live on the homepage.

Isolation

Your data lives behind your user id.

Every Shelter user's accounts, transactions, and forecasts are scoped by user id at the database layer. No table query returns another user's data. There is no shared pool, no aggregate sold to a partner, no analytics warehouse with your transactions.

Business model

Subscriptions only. That is the whole list.

Shelter is funded by subscriptions. There is no ad code in the app, no affiliate links to financial products, and no analytics partner that sees your transactions. The only way Shelter makes money is if you pay for it.

Trust is asymmetric

What we don't claim

Things Shelter has not done yet.

Trust is asymmetric. The rest of this page lists what we have done. This panel lists what we haven't. If a security review needs more than what's on this list, we're probably not the right vendor yet.

  • SOC 2 / ISO 27001 / HIPAANot certified
  • Published penetration testNone to date
  • Formal bug bountyNot running one
  • Guaranteed report-response SLABest effort only

Every claim on this page is backed by code that ships in the product today. So is every line above.

Vulnerability disclosure

Found something? Tell us.

Email support@shelter.money with a clear description and reproduction steps. We'll acknowledge on a best-effort basis within 5 business days. We don't run a formal bug bounty today, but we read every report.

Out of scope

  • Denial-of-service testing against shelter.money or the Convex backend.
  • Social engineering of Shelter staff, Plaid, Clerk, or Stripe.
  • Automated scanner output without a reproducible exploit.
  • Issues in third-party vendors (report those to the vendor directly).

Source file: .well-known/security.txt

Questions, answered

Security FAQ

Can Shelter move money out of my bank account?

No. There is no transfer or payment endpoint in the codebase. The Plaid connection is opened in read-only mode and only returns balances and transactions.

Does Shelter store my bank password?

No. Your bank credentials are entered with Plaid during the link flow. Shelter only receives a read-only access token afterward.

How is the Plaid access token stored?

Encrypted with AES-256-GCM with a fresh random initialization vector and an authentication tag per token before it is written to the database.

How does sign-in work?

Authentication is handled by Clerk. Shelter validates a Clerk-issued JWT on every request. Your password is held by Clerk; Shelter never sees or stores it.

How does payment work?

Card data is entered into Stripe’s hosted checkout, not Shelter. Shelter stores a Stripe customer id and subscription status. Your card number never reaches Shelter’s servers.

Can I revoke access?

Yes. You can unlink the bank from inside Shelter or from your bank’s third-party access settings. Revoking on either side severs Shelter’s read access immediately.

Where do I report a security concern?

Email support@shelter.money. We read every message that comes in.

Questions? Send them.

We read every email. If a security claim on this page doesn't match what you see in the product, tell us.