Security & privacy.
The subscription graph reveals your health, beliefs, politics, and routines — it’s sensitive. Tether is built so the most dangerous secrets never sit inside the app to begin with.
Secrets live outside the app
Your bank login never touches Tether — Plaid holds it. Real card numbers never touch Tether — the issuing partner vaults them. The sensitive secrets are designed to live outside our database, not merely be 'protected' inside it. Can't-leak-by-design, not trained-not-to-leak.
Encrypted at rest
The one bank token we do hold (read-only) is field-level encrypted with AES-256-GCM before it ever reaches the database, and never logged in plaintext.
Least privilege
Phase 1 requests read-only transaction access only. No money-movement scope is requested — and in this version, none exists. We read to organize your charges; we cannot move your money.
Verified webhooks
Every Plaid webhook is cryptographically verified (ES256 JWT + body hash) before Tether acts on it. A forged event does nothing.
Provable containment
Cancellations produce an Ed25519-signed receipt anyone can re-verify (the tether-containment-receipt/1 protocol). Tampering fails the check. We'd rather prove it than claim it.
Honest status
Tether is pre-launch. Security language reflects beta / unauditedstatus until an independent review completes — we don’t claim “bank-grade” or “unbreakable.” Leashes run on labeled demo cards today; real funded cards ship only after an issuing partner clears the §7.5 gate (program terms, KYC, PCI, fraud-liability, counsel). No money moves in this version.
Tether — a Perimeter product · Born Between Generals, LLC. The open receipt protocol →