Financial data demands the highest standard of protection. Here is exactly how Continuum safeguards your accounts, credentials, and personal information.
Your data is protected at every layer — from the moment it leaves your browser to the second it reaches our databases.
All connections use TLS 1.2+ encryption. Every API call between your browser, our servers, and third-party providers is encrypted end-to-end.
Sensitive provider credentials, including Plaid access tokens, are encrypted with AES-256-GCM using a dedicated ENCRYPTION_KEY that is stored separately from the database.
User passwords are hashed with bcrypt and a per-user salt. We never store plaintext passwords.
We minimize the credentials we touch — and encrypt the ones we must store.
Continuum never sees or stores your bank username or password. Plaid Link runs directly in your browser, and authentication happens between you and your bank. We only receive a read-only access token.
Connected institutions can be unlinked from account settings, which revokes Continuum's provider access for that connection.
Continuum connects to your bank accounts in read-only mode. We can see your data — but we cannot touch it.
We use Plaid in read-only mode. Continuum cannot initiate transfers, move money, or modify your bank accounts in any way.
Depending on the enabled connection, Continuum may receive balances, transactions, account metadata, liabilities, or read-only investment holdings. This access does not include payment initiation.
You can unlink any connected account at any time. Unlinking immediately revokes Continuum's access to that institution.
Multiple layers of authentication protect your account from unauthorized access.
Enable TOTP-based 2FA using any authenticator app (Google Authenticator, Authy, 1Password, etc.) for a second layer of protection on every login.
Sign in with biometrics or hardware security keys using the FIDO2/WebAuthn standard — phishing-resistant authentication with no passwords to steal.
Active sessions are tracked with device and location metadata. You can review and revoke sessions from your settings at any time. Sessions expire automatically after inactivity.
Your financial data belongs to you. We enforce strict boundaries around who can see what.
Continuum does not sell, rent, or share your personal financial data with advertisers, data brokers, or any third party for marketing purposes.
All data is scoped to your household. There is no cross-household data leakage — every database query is filtered by household ID at the service layer.
Administrative actions are role-gated (only admin and owner roles) and logged to an audit trail. Every admin action is recorded with the acting user, timestamp, and details of what changed.
We take security seriously and are happy to answer any questions about how we protect your data. Reach out any time.
Contact Security Team