Why we default to read-only bank access
Connecting your bank should never mean handing over the keys. A short note on why Cirrus only ever reads, never moves, your money.
When you link an account to Cirrus, we ask for read-only access. That means we can see balances and transactions to build your dashboard, but we cannot move a single dollar. This is a deliberate choice, and we think every finance app should make it.
The principle: least privilege
A tool should only get the access it genuinely needs. Cirrus needs to read your data to show you a clear picture. It does not need the ability to send payments, so it never asks for it. Less access means less that can go wrong.
How the connection works
We link through trusted aggregators using bank-grade encryption, and we never store your banking credentials. The connection can be revoked from your bank or from Cirrus at any time, and revoking it removes our access immediately.
Why it matters even if nothing goes wrong
Read-only access is not only about worst-case scenarios. It is about peace of mind. Knowing an app literally cannot touch your money makes it easier to connect everything and get the full picture, which is the whole point.