Security

Security & Data Protection

Your money picture is personal. Here's how OnNest protects it, and the controls you have over it. Last updated 8 September 2026.

Only you can reach your information

Your OnNest information is behind sign-in, and the database itself is set up so records are reachable only by your own account — not just the screens you see.

Administrative accounts use MFA

The accounts used to operate OnNest — the platform, the backend and the financial-data provider dashboard — all require multi-factor authentication.

Provider credentials stay on the server

Sensitive credentials used to talk to a financial-data provider are server-only. Access tokens for a connected institution are never sent to your browser and are never shown to you or anyone else.

Protected in transit and at rest

OnNest is served over HTTPS, so traffic between you and OnNest is encrypted. The managed infrastructure OnNest runs on provides encryption protections for stored data.

Security is treated as part of the product

OnNest holds a picture of someone's financial life, and that deserves to be taken seriously. Security controls are written down, reviewed and tested rather than assumed.

Testing and scanning

OnNest runs an automated test suite covering, among other things, who can reach which information, what a downloaded copy may contain, and what deletion actually removes. Dependency scanning and platform security scanning are run to catch known weaknesses in the software OnNest depends on and in its access rules.

OnNest holds no security certification and does not claim one. What is described here is what OnNest actually does.

Connected financial institutions

Connecting an institution will always be optional, and OnNest works fully without it. When connections are available:

  • You authorise each connection yourself, and OnNest does not receive your online banking password.
  • You can disconnect an institution at any time, which stops anything further being gathered.
  • You can separately delete the connected information OnNest already gathered, without touching the figures you entered yourself.

You stay in control of your information

  • Download a copy of your OnNest information whenever you want.
  • Correct anything you entered yourself.
  • Delete your OnNest account permanently.

See Privacy Choices & Data Rights for how to use each of these.

Reporting a security concern

If you spot something that looks wrong, tell us at support@getonnest.com. Good-faith reports are welcome, taken seriously and investigated.

This page describes protections in general terms on purpose. OnNest doesn't publish the internal details of how its defences are built.