Lait

Trust & security

How Lait protects your money and your data, in plain language. No jargon, no certifications we do not hold, no fine print that contradicts this page.

Last reviewed: September 27, 2026

Read-only access
Encrypted, in transit and at rest
Database in the EU
Export or delete, anytime
On this page
01

How we protect you

Read-only by design

Bank and broker connections are read-only under PSD2. We can never move, transfer or spend your money.

Encrypted at rest and in transit

AES-256 at rest, TLS 1.3 in transit. Exchange API keys get a second layer of AES-256-GCM before they touch the database.

Your data, only yours

Sign-in is handled by Clerk. Every request is scoped to your account; there is no shared view.

Database in the EU

Your financial data lives in Frankfurt (Neon Postgres). Where each processor runs is listed below, not hidden.

We never sell your data

No advertisers, no data brokers, no credit scoring. Ever.

Export or delete everything

From Settings you can export all your data (JSON or CSV) or erase your account and every row we hold.

02

Read-only Open Banking (PSD2)

When you connect a bank, Lait uses Enable Banking, a licensed Account Information Service Provider (AISP) under PSD2. The connection is read-only by law and by design: we see balances and transactions to build your dashboard, and we can never initiate a payment or move funds.

You authorize every connection on your own bank's login and consent screen. We never see or store your banking password. Lait caps each consent at 90 days; it never renews without you, and revoking it from Settings withdraws the consent at the bank side too, not just in our database.

Broker connections through SnapTrade follow the same rule: read-only, authorized by you, revocable.

Direct bank connections are rolling out gradually. Until they reach your account, bank data comes in through the statements you upload (CSV or Excel), which give Lait no access to your bank at all.

03

Encryption & credentials

Data is encrypted at rest with AES-256 and in transit with TLS 1.3. Exchange API keys you add are encrypted a second time at the application layer (AES-256-GCM, with a key that lives only in the server environment) and are never returned by any API response. Wherever the exchange allows it, we ask for read-only keys, so even a leaked key could not move your assets.

04

Authentication & access

Sign-in is managed by Clerk, a dedicated authentication provider; Lait never handles your password. Every request is scoped to your account: there is no shared view and no way to reach another user's data through the API. Administrative access is restricted to the platform operator, for support and maintenance only.

05

Where your data lives

Your database is Neon Postgres in Frankfurt (EU). The application runs on Vercel: pages are served from the edge location nearest to you, and the server functions that process your requests run in Frankfurt (EU), next to the database. Some processors in the table are US companies (sign-in, email, error reports, payments, AI models); each of those transfers is covered by the EU Standard Contractual Clauses in our Data Processing Agreements. We list them plainly instead of claiming "100% EU".

As a European service we operate under the GDPR: you can access, correct, export or delete your data at any time. To exercise any right, write to privacy@lait.finance.

06

Who touches your data

Every third party that processes any of your data, what it sees and where it runs. The same list as our Privacy Policy, in one table.

  • Enable BankingRegulated AISP · rolling out
    EU

    Bank connections under PSD2

    Sees: Balances and transactions

  • SnapTrade
    Canada, and the US per its policy

    Read-only brokerage connections

    Sees: Holdings and balances

  • Clerk
    US

    Sign-in and sessions

    Sees: Email, name, login data

  • Neon
    EU · Frankfurt

    Database

    Sees: Your financial data

  • Vercel
    Edge worldwide · functions in EU · Frankfurt

    Hosting, server functions, attached files, cookieless analytics

    Sees: App traffic and the files you attach

  • Upstash
    EU · Frankfurt

    Short-lived cache

    Sees: Market quotes, short-lived copies of your data (expire within 40 days, most in minutes), IP counters against abuse (2 minutes)

  • Stripeoptional
    EU · Ireland, US

    Payments for Premium

    Sees: Email, name and billing details. Your card goes to Stripe, never to Lait

  • Resend
    US

    Account, support and summary emails

    Sees: Email and name; what a summary contains, only if you turn summaries on

  • Sentry
    EU · Frankfurt

    Error reports

    Sees: Diagnostics when an error happens, no session recording, no personal-data fields by default

  • Cloudflare
    US

    Domain and email forwarding

    Sees: The emails you send to our addresses, in transit

  • OpenAIoptional
    US

    Transaction categorization, advisor, budget note

    Sees: Transaction descriptions, portfolio context and the note you write for your budget, without IBANs, emails or phone numbers

  • Anthropicoptional
    US

    Advisor (Claude)

    Sees: Portfolio context, without IBANs, emails or phone numbers

  • TypeSafeoptional
    US

    Advisor reply check, routing, category review, bug triage, support prioritisation

    Sees: The text of the advisor's replies (which can repeat figures from your portfolio) and, when switched on, your question or palette search, transaction descriptions with their proposed category, bug reports and aggregated account facts — without IBANs, emails, names or phone numbers; it returns only categories and probabilities

  • Googleoptional
    US

    Categorization, research, valuations, translation, reading documents you ask it to

    Sees: Transaction descriptions, tickers, headlines, the asset documents you ask it to read

US providers are covered by the EU-US Data Privacy Framework or the EU Standard Contractual Clauses in each Data Processing Agreement. Canada holds an EU adequacy decision; SnapTrade says it may also process data in the US. Optional providers only see anything if you use that feature: AI if you use AI, Stripe if you subscribe.

07

Optional AI, minimum context

AI features are optional; Lait works completely without them. When you use one, we send only the minimum context the answer needs, and never your credentials. Before any transaction leaves for a model, we strip IBANs, emails, phone numbers and account numbers. We use these providers to answer you and for the checks our Privacy Policy lists, never for advertising. And nothing you share trains a model: every provider is used under its API terms, where inputs are not used for training. Your data is not the product, now or ever.

08

We never sell your data

Your financial data is used only to build your portfolio, categorize your transactions and power the features you asked for. We do not use it for advertising or credit scoring, and we do not sell, rent or share it with advertisers or data brokers. The one profile we build is the support prioritisation our Privacy Policy describes: it never changes what you can use or pay, and you can object to it. The processors in the table are the complete list; reading a wallet or an exchange also means asking that service, with the public address or read-only key you gave us.

09

We tell you when a sync breaks

When a source stops syncing (an exchange key revoked, a wallet provider down, a bank consent about to lapse), we show the real error instead of letting your numbers go stale in silence. Sources are checked when you open the app, at most every six hours, and connected banks three times a day in the background, so you always know whether what you see is current.

Revolut · sync failed

Consent invalid · 401 Unauthorized

The exact alert you would see.

10

Export and delete, no tickets

From Settings you can export everything you have in Lait as JSON or CSV, and delete your account. Deletion erases every row we hold about you, withdraws your bank consents at the bank side, removes any photos or documents you attached, and closes your sign-in account. No email, no waiting.

11

Report a vulnerability

Found something? Write to security@lait.finance and a real person reads it. We do not run a bug bounty and we are not SOC 2 or ISO 27001 certified; we are a small team and will not pretend otherwise. What we will do is answer, fix, and credit you if you want. Our contact is also published at /.well-known/security.txt (RFC 9116).

12

Questions

Security questions, data requests, or you just want to dig deeper? Write to a real person.

Lait is operated by Mistinguett Capital Investments, S.L. (València, Spain).

LaitLive Asset Intelligence
València