Yarrow

Security

Effective October 8, 2026

In plain English

  • Yarrow can read your bank data. It can't move money.
  • Your bank password goes to your bank through Plaid. We never see it.
  • The token that keeps your bank connected is encrypted, and everything travels over TLS.
  • Found a security problem? Email boston@yarrow.money.

How your bank connects

Yarrow uses Plaid to connect to your bank. When you connect, Plaid opens a secure window in the app. You sign in to your bank there, and you choose which accounts to share. Your bank username and password go to Plaid and your bank, never to Yarrow.

Plaid then gives our server an access token. It lets Yarrow read balances, transactions and, where your bank provides them, card and loan details such as the interest rate and minimum payment. The access is read-only. Yarrow can't move money, make payments or change anything at your bank.

You can disconnect a bank at any time in the app. When you do, or when you delete your account, we tell Plaid to remove the connection and we delete that bank's data from our systems. You can also review and remove connections through Plaid at my.plaid.com.

How we protect your data

  • Encrypted bank tokens. Plaid access tokens are encrypted with AES-256-GCM before they're stored. The key is held in a secrets manager, separate from the data, and tokens never go to your phone.
  • Encrypted in transit. The app, our servers, Plaid and Apple talk only over HTTPS (TLS).
  • Encrypted at rest. Your data is stored in Amazon Web Services databases in the United States, encrypted at rest.
  • Least privilege. Our server is allowed to reach only its own database, its own secrets and its logs. Development and production run in separate AWS accounts, so test systems never touch real data.
  • No passwords to steal. You sign in with Apple. Yarrow has no password of its own. Your session key is kept in your iPhone's Keychain, and our server stores only a one-way hash of it.
  • Short-lived logs. Server logs are deleted after 14 days.
  • No ad or tracking SDKs. The app has no advertising or analytics code from third parties.
  • No third-party AI. We don't send your bank data to outside AI services.

What we're honest about

Yarrow is made by a small company. We don't have a SOC 2 report or an outside security audit yet. No system is perfectly secure, and if something ever goes wrong with your data, we'll tell you what happened, what it affects and what we're doing about it, as the law requires and as soon as we can.

What you can do

  • Keep a passcode and Face ID or Touch ID on your iPhone, and keep iOS up to date.
  • Use a strong, unique password and two-factor sign-in at your bank.
  • Disconnect banks you no longer want Yarrow to see.
  • Yarrow will never ask for your bank password by email, text or phone. If someone does, it isn't us.

Report a vulnerability

If you think you've found a security problem in Yarrow, the app or this website, email boston@yarrow.money with "Security" in the subject. Tell us what you found and how to reproduce it. We'll confirm we got it and keep you posted while we fix it.

Please give us a reasonable time to fix the problem before telling anyone else, don't access or change other people's data, and don't run tests that could degrade the service, such as denial of service or spam. If you act in good faith and follow these rules, we won't pursue legal action against you for your research.

We don't run a paid bug bounty yet.