Read-only by design: why finura can’t move your money
The architectural decision that removes a whole class of risk — and what it means for you.
The safest way to handle a capability is to not have it. finura connects to your banks through read-only aggregation: we can see balances and transactions, and we cannot initiate a transfer, a payment, or a withdrawal. Not "we choose not to" — we structurally can't.
What "read-only" actually removes
A tool that can move money has to defend every path an attacker might use to make it do so. A read-only tool deletes that entire category of risk.
- No payment rails means no fraudulent-transfer surface.
- A leaked finura credential exposes visibility, never control.
- Support staff and internal systems have nothing to abuse, because the capability was never built.
The tradeoff, stated honestly
Read-only means finura will never be the app you pay a bill from. That is a real limitation, and we are choosing it deliberately. For a tool whose job is to give you one precise, trustworthy view of your money, the ability to move that money is not a feature — it is a liability we would rather not carry on your behalf.
Security you have to trust us to maintain is weaker than security that isn't possible to breach.
Encryption and connections
Underneath, connections run through established aggregation (Plaid and equivalents) so your bank credentials are never seen or stored by finura, and data is encrypted in transit and at rest. But the architecture is the headline: the strongest guarantee we can give you is the one that doesn't depend on us being perfect.
David is the founder of finura, building a personal finance platform for people whose money crosses borders and currencies.