Your financial data is sacred. We use strong encryption and security best practices to keep it protected.
Active
AES-256 encryption at rest and TLS 1.3 in transit.
Active
We minimize data collection and never sell your data.
Active
All billing handled by Stripe, a PCI Level 1 certified processor.
Active
Error tracking and uptime monitoring via Sentry and BetterUptime.
We implement industry-leading security practices across every layer of our infrastructure.
We're happy to discuss our security practices and answer any questions about how we protect your data.
All financial data is encrypted using AES-256 encryption at rest and TLS 1.3 in transit. We never store raw banking credentials—all bank connections go through Plaid with tokenized access.
Only you and team members you explicitly invite can access your data. Our engineering team cannot view your data without explicit written permission for support purposes, and all access is logged.
Data is stored securely in managed PostgreSQL on Railway’s infrastructure in the United States with regular backups.
In the unlikely event of a breach, affected customers are notified promptly with full transparency about the scope and remediation steps.
We’re building self-service data export. In the meantime, contact us at [email protected] to request your data or account deletion.
Absolutely not. We never sell, share, or monetize your data. Your financial information is used solely to provide the culta.ai service to you.
Our security team is happy to answer any questions about how we protect your data.
Contact security team