Cilantro

Security

How we protect your financial data, in plain English. Read our Privacy Policy for the full legal-grade version.

Encryption

Authentication

Bank connectivity (Plaid)

AI features (Anthropic)

Hosting and access control

What we don't do

Incident response

If we discover a security incident affecting your data, we will notify affected users by email within 72 hours of confirming the incident, with a description of what happened, what data was involved, and what you should do (if anything). We log production access continuously to speed up forensic review.

Reporting a vulnerability

Found something concerning? Email security@highloop.co (or support@highloop.co if the former bounces). We respond to all good-faith reports within 5 business days. Please don't publish the details until we've had a chance to fix them.