How it works FIRE concepts Pricing Sign in
Trust

Security

Last updated August 19, 2026

Privacy notice Terms of service Security

Security is foundational to Gentry. We hold financial data that matters to you, and we treat protecting it as a core part of the product. This page summarizes the practices we follow today.

1. Brokerage Credentials and Connections

Gentry never sees or stores the credentials to your brokerage, bank, or other financial institutions. That is a commitment about how we build, not a description of what we happen to support this month.

Connecting an account is never required. Gentry works entirely on numbers you enter yourself: you add your account labels, holdings, and transactions, and we keep the prices fresh from public market data feeds. Manual entry is a first-class way to use Gentry and it is staying that way.

When you do connect an account, you authenticate with your institution through a specialist data provider, entering your details into that provider's own secure interface or your institution's login screen, never into Gentry. The provider holds that relationship, not us. We receive read-only information such as balances and holdings. We cannot move money, place trades, or change anything at your institution. You can disconnect at any time, which revokes our access to that account.

2. Encryption

  • In transit. All traffic to and from the Service is encrypted with industry-standard TLS (HTTPS). HTTP requests are redirected to HTTPS, and modern cipher suites are enforced.
  • At rest. Production databases and backups are encrypted at rest using disk-level encryption provided by our cloud infrastructure provider.

3. Authentication

Accounts are authenticated through our identity provider. You can sign in with an email and password or with a supported third-party provider such as Google. Passwords are never stored by us in plain text; they are handled and salted-hash-stored by the identity provider. We strongly recommend enabling two-factor authentication on the third-party provider you use to sign in.

4. Session Management

The Service uses HTTP-only, secure session cookies bound to your browser. Sessions are verified on every protected request. Signing out invalidates your session. We rotate session keys regularly and revoke them when we detect suspicious activity.

5. Access Controls

Access to production systems and customer data is restricted to the smallest number of authorized engineers needed to operate the Service. Privileged access requires strong authentication, is logged, and is reviewed periodically.

6. Infrastructure

The Service runs on reputable cloud infrastructure with physical, network, and operational security controls maintained by the provider. Production workloads are isolated from development and test environments. We apply security patches to our dependencies on a regular cadence.

7. Monitoring and Logging

We monitor application and infrastructure logs for errors, anomalies, and suspicious activity. Logs are retained for a limited period for security and reliability purposes. We review alerts and respond to incidents according to a documented playbook.

8. Backups and Recovery

Customer data is backed up on a regular schedule. Backups are encrypted and retained for a defined window. We periodically test our ability to restore from backup so a recovery is not the first time we exercise the process.

9. Data Minimization

We collect only the information we need to operate the Service. We do not sell your personal information. See our Privacy Notice for the full picture of what we collect and how we use it.

10. Your Role

You play a key part in keeping your account safe. We recommend:

  • Use a strong, unique password and a password manager.
  • Enable two-factor authentication on the email or identity provider you use to sign in.
  • Sign out of shared or public devices when you are done.
  • Be cautious of phishing. We will never ask for your password by email or chat.

11. Responsible Disclosure

If you believe you have found a security vulnerability in the Service, please report it to us at security@gentry.money. Provide enough detail for us to reproduce the issue. We ask that you give us a reasonable opportunity to investigate and remediate before public disclosure, and that you avoid accessing data that is not your own, degrading the Service, or otherwise harming users. We appreciate the research community and will work in good faith with responsible researchers.

12. Contact

For other security questions, please email security@gentry.money.

© 2026 Gentry. Plant a seed. Cultivate freedom. AboutEmbedWhat's NewPrivacyTermsSecurity