Security

Security built around your portfolio

Your investments remain with your existing financial institutions. Palance uses secure, read-only connections to bring your portfolio data together without taking custody of your assets or requiring the ability to trade.

READ-ONLY ACCESS·NO CUSTODY·NO TRADING AUTHORITY

Your money stays where it is

Palance sits above your existing accounts as an analytics layer. It does not become the custodian of your investments or replace the institutions that hold them.

  • Palance does not custody your assets.
  • Your investments remain with your brokers, custodians and financial institutions.
  • Palance does not move money or initiate transfers on your behalf.
01 / CUSTODY
Assets remain at your institution
The connection brings portfolio information into Palance. It does not bring the underlying assets into Palance.
02 / MOVEMENT
No authority to move funds
Palance does not request transfer authority and cannot withdraw cash or move securities through the analytics connection.
03 / PURPOSE
Data for portfolio analysis
Connected account data is used to consolidate holdings and calculate the portfolio analytics you choose to view.
02 / Connection permissions

Read-only by design

Brokerage connections retrieve the account, position, balance and activity information required to analyze your portfolio. Palance requests data access only. The connection is not intended to give Palance authority to execute trades, transfer funds or take control of your account.

Open the connection flow
Brokerage infrastructure

Secure connections through SnapTrade

Palance uses SnapTrade's connection infrastructure for supported brokerage integrations.

  • Where supported by the financial institution, authentication takes place through OAuth directly with the brokerage.
  • Palance does not ask you to enter brokerage credentials directly into Palance.
  • Where OAuth is not supported, authentication is handled through SnapTrade's secure Connection Portal. Depending on the institution, SnapTrade may securely handle the credentials needed to maintain that connection.
01

Your brokerage

Your financial institution continues to hold your cash and investments.

02

SnapTrade

The secure portal facilitates authentication and the supported data connection.

03

Palance analytics

Palance organizes the permitted portfolio data into a consolidated analytical view.

SnapTrade infrastructure

Security infrastructure

The measures below describe SnapTrade's infrastructure and certifications. They are not presented as certifications held independently by Palance.

01
SOC 2 Type II
SnapTrade states that its systems and processes are SOC 2 Type II certified.
02
Encrypted in transit and at rest
SnapTrade states that data is protected in transit using TLS and encrypted at rest.
03
AWS KMS protection
For institutions that require credentials rather than OAuth, SnapTrade states that sensitive credentials are stored and encrypted using AWS KMS.
04
Signed API requests
Data exchanged between SnapTrade and authorized applications is authenticated using a cryptographic signature for each request.
05
Independent testing
SnapTrade works with third-party security firms to conduct penetration testing.
06
Responsible disclosure
SnapTrade maintains bug-bounty and responsible-vulnerability-disclosure practices.

You're in control

A connection should remain useful only while you want it. Supported brokerage connections can be disconnected, and authorization can be revoked through the relevant institution or connection flow.

01

Disconnect

Stop a supported connection when you no longer want Palance to retrieve updated account data.

02

Revoke

Connection access can be revoked. If authorization expires, fresh data remains unavailable until you choose to reconnect.

03

Delete

Account deletion removes active portfolio, preference, custom benchmark and brokerage-connection data, subject to the limited legal-retention cases described in our Privacy Policy.

· Begin securely

Bring your portfolio together without moving it.

Connect a supported institution through a read-only flow, or start with a manual portfolio if you prefer.

Connect a brokerage