Back to homeSecurity

Security starts with asking for less.

Dracit does not connect to your bank or provide a field for card-number entry. A statement you choose to upload can still contain financial and account identifiers, so the safeguards below describe how that data is handled.

Last updated: September 4, 2026

No bank login

Nothing connects to your bank. There is no credential to phish or store.

No card-number entry

The wallet needs a card name, not a typed PAN.

Local-first

The rewards math starts from restraint: less sensitive data collected in the first place.

Security by architecture

Most financial tools ask you to connect your bank, then spend enormous effort protecting the credentials and account data they gathered. Dracit does not request bank credentials and limits what it intentionally retains after parsing a statement. The attack surface is smaller because less sensitive data is requested and retained.

No bank credentials

Dracit has no integration with online banking and no screen that requests a banking username or password. You add cards by name and upload a statement you already downloaded yourself. If any service claiming to be Dracit asks for your bank login, it is not us.

No card-number entry

Rewards calculations depend on a card's category earn rate, not its account number. Dracit only needs the card name, and there is no input for a card number, CVV, or expiry date. A statement you choose to upload can contain account or card identifiers. Dracit receives the complete file while parsing it, retains the supplied filename and parsed statement data, and does not intentionally persist the original file after parsing.

Encryption and transport

Production traffic should run over HTTPS/TLS. Dracit's self-hosted database and backups are controlled by the deployment environment, so encryption at rest depends on host configuration, disk encryption, database controls, backups, and operator procedures.

Authentication

Dracit supports a password account with email verification. It stores a one-way hash of your password, not your plaintext password, and uses bounded one-time links for verification and reset. Google sign-in is optional and used for identity only; Dracit does not receive or store your Google password. Google access is limited to the profile information required to confirm identity, not Gmail, Drive, contacts, or financial accounts.

Data minimization and retention

Dracit collects the information required for the current service. You can remove an uploaded statement in Statements; this removes its statement record and associated transactions from the active database. Account deletion is not self-service, but you can request it from the Dracit Privacy Lead at support@dracit.ca. Backup and log retention is separate from self-service statement deletion; no owner-approved retention schedule is currently configured.

Responsible disclosure

No public security-disclosure mailbox is active yet. Before launch, Dracit must publish and verify a monitored disclosure channel. Do not send vulnerability details to an unproven address, access another user's account, exfiltrate data, run destructive tests, or attempt denial-of-service testing without written authorization.

Your part

  • Download statements from your bank's official site or app, and delete the original file once upload and review are complete.
  • Use a strong, unique Dracit password. If you link Google, protect that Google account with a strong password and two-factor authentication.
  • Remember that Dracit will never ask for a bank login, card number, or one-time passcode.
Note

This page describes Dracit's security posture in plain language. Formal controls, certifications, and infrastructure details should be confirmed by qualified security reviewers before launch.

Trust, then verify

Read the math, not your money.

See exactly how the audit works. Every dollar of missed rewards traces to a rate you can check.

How the math works