Security at TruMint

Last updated: May 2026

TruMint holds some of the most sensitive data you have — your holdings, transactions, net worth, and tax details. We treat protecting it as the core of the product, not an afterthought. This page explains, in plain English, exactly how we do that.

We can never move your money

TruMint connects to your brokers and banks in read-only mode. We can see balances and transactions to build your portfolio and tax picture — but we cannot move, withdraw, or trade your money, and we never ask for permissions that would let us. There is no payment capability in the product.

Your data is encrypted — and even we can't casually read it

All traffic is encrypted in transit (TLS). More importantly, your sensitive financial data — amounts, transaction details, holdings, tax calculations, your National Insurance number, and uploaded documents (P60s, statements) — is encrypted at rest with a key unique to your account.

Those keys are protected by a hardware-backed key service (Google Cloud KMS). The ability to decrypt is granted only to TruMint’s production system no member of staff holds it. Any change to who can access encryption keys is logged and triggers an automatic alert, so it can never happen quietly. In day-to-day operations, our engineers see encrypted data, not your figures.

We never store your bank or broker login details

When you connect an account through open banking, we use secure, revocable access tokens — we never see or store your bank username or password. Those tokens are themselves encrypted, and you can disconnect any account at any time.

Where your data lives

TruMint runs on Google Cloud. Your data is stored encrypted, and the encryption keys that protect it are managed in the United Kingdom (London). Because the data is encrypted with UK-managed keys, it is unreadable wherever the underlying storage is hosted.

We never sell your data

You are our customer, not our product. We do not sell, rent, or share your personal or financial data with advertisers or data brokers. We use your data only to provide the service to you. See our Privacy Policy for the full detail.

Your data, your control

Under UK GDPR you have the right to access, export, correct, or delete your data. You can request any of these — including full deletion of your account and its data — by contacting us. When data is deleted, your per-account encryption key is destroyed, which renders the underlying data permanently unrecoverable.

Reporting a security issue

If you believe you’ve found a vulnerability, please tell us at security@trumint.co. We welcome responsible disclosure and will work with you to confirm and fix issues promptly. Please don’t access other users’ data or degrade the service while testing.

What we’re continuing to improve

Security is never “done.” Work in progress includes multi-factor authentication, independent third-party security certification, and further reducing the number of systems that ever handle decrypted data. We’ll update this page as these land.

Questions about how we protect your data? Email support@trumint.co.