Back to home
Trust & Security

Security at Chekkd

A plain-language view of how we protect verification and connection information.

Last reviewed: July 6, 2026

Protecting information in transit and at rest

Chekkd uses TLS for supported client-to-service connections. Sensitive provider access tokens used to maintain a Plaid Bank connection are encrypted at rest and are not returned to the browser.

Access to production systems and customer records is limited through authentication, authorization, and operational access controls. No system can guarantee absolute security.

Bank connection boundaries

Plaid Link handles the connection to your financial institution. Chekkd does not receive your bank username or password.

The current Level 4 Bank flow does not request or store bank transactions, transaction history, purchases, merchant activity, spending categories, or bank statements, and Chekkd does not use the connection to move money.

For current connections, Chekkd keeps the encrypted provider token, Item identifier, institution and selected masked account metadata, connection health, and related operational timestamps needed to manage the connection. Bank-management endpoints require an authenticated user and verify ownership of the connection.

Earlier Bank versions may have created bank identity, identity-match, balance-snapshot, or related derived records. They are not used by the current Bank flow and remain subject to a reviewed retention and deletion decision described in the Privacy Policy.

Provider messages and lifecycle events

Chekkd verifies signed Plaid webhook messages before using them to update connection health. Current lifecycle handling processes each verified message and its health update atomically so repeated provider notifications do not create duplicate state changes.

Current application logs and analytics are designed to exclude provider tokens, complete account or routing numbers, bank details, bank credentials, and raw verification payloads. New webhook receipts retain only limited event metadata rather than the raw provider message.

Identity Verification

Plaid Identity Verification handles government-document and liveness capture. Chekkd does not store raw ID photos, identity-document image files, or Plaid biometric templates. Chekkd keeps the limited provider references, results, and identity fields described in our Privacy Policy to operate the verification record.

Your controls

  • Manage or disconnect individual Bank connections from Linked Accounts.
  • Control public Passport and profile visibility from Privacy settings.
  • Review active sessions and account security from Security settings after signing in.
  • Request access, correction, or deletion by contacting support@chekkd.com.

Report a concern

If you believe your Chekkd account or information is at risk, contact support@chekkd.com. Do not send passwords, bank credentials, account numbers, identity documents, or other sensitive information by email.