Security
Nectarine is built so your advisor can help you make better decisions — without ever being able to move money out of your accounts. Here's how we protect your data, your documents, and your finances.
Can Nectarine move my money?
No. When you connect a bank or investment account, we use Plaid in read-only mode. We can see balances, transactions, and investments so your advisor can give informed advice. We cannot initiate transfers, payments, or withdrawals from those linked accounts.
- We never receive or store your bank login credentials — you authenticate directly with your institution through Plaid.
- Paying for advice is separate: fees are collected through Stripe (hosted checkout / invoices), not by debiting accounts you linked via Plaid.
How we connect to your accounts
Account linking uses Plaid, a widely used financial data network trusted by thousands of apps and banks. You choose which institutions to connect, and you can disconnect any linked account from your Nectarine account at any time.
- US institutions only.
- Read access for accounts, transactions, and investments (for advice and planning).
- Learn more about how Plaid protects consumers: plaid.com/safety.
Paying for advice
Advisory fees (for example The Hour, The Plan, or The Ongoing) are charged through Stripe's hosted payment pages. Your card details are handled by Stripe; they are not stored on Nectarine's servers. Your Plaid-linked accounts are never used to collect payment.
Stripe's security practices are described at stripe.com/docs/security.
Data security & encryption
We protect your information in transit and at rest, and we limit who can open sensitive files.
- In transit: Connections to Nectarine use HTTPS/TLS. We also use HTTP Strict Transport Security (HSTS) in production.
- Documents at rest: Files you upload (for example statements or tax returns) are stored in private Amazon S3 buckets with server-side encryption using AES-256 (Amazon S3 managed keys, SSE-S3).
- Temporary download links: When you or your advisor download a file, access is via a short-lived link that expires after about two hours — not a permanent public URL.
- Access controls & logging: Viewing or downloading documents requires a signed-in user with permission (you, your assigned advisor, or authorized support). Access attempts and downloads are logged for audit purposes.
Note on encryption: we use industry-standard transport and storage encryption. We do not use zero-knowledge or client-side encryption for documents, because your advisor needs to be able to open and review the files you share as part of the engagement.
Account security & two-factor authentication
Your Nectarine account is password-protected and supports two-factor authentication (2FA).
- Email codes: A one-time code sent to your email when signing in with 2FA enabled.
- Authenticator app (optional): You can enroll a TOTP app (Google Authenticator, Authy, 1Password, and similar) and receive recovery codes if you lose access to your device.
- Sessions: We use short-lived access tokens plus an HttpOnly refresh cookie that is rotated on use, so session credentials are harder to steal via scripts in the browser.
- Password reset: Resets go through a verified email flow — never over insecure channels from our support team asking for your password.
You can manage 2FA from your account security settings after you sign in.
System & infrastructure security
Nectarine runs on Amazon Web Services (AWS), with application hosting, a managed database, and object storage separated by purpose.
- Application: Hosted on AWS Elastic Beanstalk.
- Database: PostgreSQL on Amazon RDS.
- Files: Private Amazon S3 buckets for uploads and related materials.
- Authorization: Sensitive records are gated by per-entity access checks (client, advisor relationship, or admin), with access request logging.
More on AWS security: aws.amazon.com/security.
Providers we trust
We rely on specialized vendors for connectivity, payments, email, and meetings. Below are the main providers that may touch customer data or credentials in the course of using Nectarine:
- Plaid — secure, read-only account connectivity (you authenticate with your bank through Plaid).
- Stripe — advisory fee payments and invoices.
- Amazon Web Services — hosting, database, and encrypted file storage.
- SendGrid — transactional email (for example notifications and verification codes).
- Zoom — advisor meetings; when recordings are enabled for an engagement, recordings may be stored securely in our systems for the advisory relationship.
Your controls
- Disconnect any Plaid-linked institution from your account at any time.
- Upload, rename, or delete documents you no longer want stored (subject to engagement rules for deliverables).
- Review how we handle personal information in our Privacy Policy and the rules of use in our Terms of Use.
Questions
If you have a security question or want to report a concern, please contact us. We take these reports seriously and will respond as quickly as we can.