Security
How BankLink keeps your banking data secure
Connecting a bank account is a matter of trust. Every connection is opt-in, credentials are encrypted and never stored in plaintext, every request is logged, and access is revocable at any point.
Security controls
Encrypted in transit and at rest
TLS 1.2+ for all API traffic; AES-256-GCM for stored credentials and sensitive data.
No plaintext credentials
Bank login credentials are encrypted with AES-256-GCM and are never stored in plaintext.
Consent-first access
No account is accessed without the account holder’s explicit authorisation.
Full audit trail
Every user action and API request is logged and attributable.
Revocable access
Linked accounts and API keys can be disconnected or revoked at any time.
Scoped API keys
Keys are hashed and created with the minimum permissions required.
POPIA-aligned
Built in line with South Africa’s Protection of Personal Information Act (POPIA), 2013.
ISO 27001 controls
Designed against ISO/IEC 27001:2022 controls; formal certification is in progress.
How credential security works
When you link a bank account, the login credentials are encrypted with AES-256-GCM before they are stored, and they are kept separate from your transaction data. They are never written to logs, never returned by the API, and never stored in plaintext. All API traffic runs over HTTPS (TLS 1.2 or higher).
Data access and consent
BankLink only accesses an account with the account holder’s explicit consent. Every request is logged and attributable through a full audit trail, API keys are scoped to the minimum permissions required, and you can disconnect an account or revoke a key at any time to stop further access immediately.
Compliance
BankLink is built in line with South Africa’s Protection of Personal Information Act (POPIA), 2013, and is designed against ISO/IEC 27001:2022 information-security controls. Formal ISO 27001 certification is in progress — we describe our posture as controls-aligned rather than certified until that audit completes.
Frequently asked questions
Is it safe to connect my bank account to BankLink?
Yes. Access is opt-in and only happens with your explicit authorisation, your credentials are encrypted with AES-256-GCM and never stored in plaintext, every request is logged, and you can disconnect at any time.
How are my bank credentials stored?
Credentials are encrypted with AES-256-GCM and stored separately from other data. They are never written to logs or stored in plaintext.
Is BankLink POPIA compliant?
BankLink is built in line with South Africa’s Protection of Personal Information Act (POPIA), 2013 — consent-first access, data minimisation, auditability, and the ability to revoke access and have data removed.
Can I revoke BankLink’s access to my account?
Yes. You can disconnect a linked account or revoke an API key at any time, which immediately stops further access.
Is BankLink ISO 27001 certified?
BankLink is designed against ISO/IEC 27001:2022 controls. Formal certification is in progress; we describe our current posture as controls-aligned rather than certified.
Who can see my banking data?
Only you and the people or systems you authorise within your organisation. Access is scoped, logged, and attributable; data is not shared without your consent.
See what you can build on the features page, or get started.