No bank login
Nothing connects to your bank. There is no credential to phish or store.
Last updated: September 4, 2026
Nothing connects to your bank. There is no credential to phish or store.
The wallet needs a card name, not a typed PAN.
The rewards math starts from restraint: less sensitive data collected in the first place.
Most financial tools ask you to connect your bank, then spend enormous effort protecting the credentials and account data they gathered. Dracit does not request bank credentials and limits what it intentionally retains after parsing a statement. The attack surface is smaller because less sensitive data is requested and retained.
Dracit has no integration with online banking and no screen that requests a banking username or password. You add cards by name and upload a statement you already downloaded yourself. If any service claiming to be Dracit asks for your bank login, it is not us.
Rewards calculations depend on a card's category earn rate, not its account number. Dracit only needs the card name, and there is no input for a card number, CVV, or expiry date. A statement you choose to upload can contain account or card identifiers. Dracit receives the complete file while parsing it, retains the supplied filename and parsed statement data, and does not intentionally persist the original file after parsing.
Production traffic should run over HTTPS/TLS. Dracit's self-hosted database and backups are controlled by the deployment environment, so encryption at rest depends on host configuration, disk encryption, database controls, backups, and operator procedures.
Dracit supports a password account with email verification. It stores a one-way hash of your password, not your plaintext password, and uses bounded one-time links for verification and reset. Google sign-in is optional and used for identity only; Dracit does not receive or store your Google password. Google access is limited to the profile information required to confirm identity, not Gmail, Drive, contacts, or financial accounts.
Dracit collects the information required for the current service. You can remove an uploaded statement in Statements; this removes its statement record and associated transactions from the active database. Account deletion is not self-service, but you can request it from the Dracit Privacy Lead at support@dracit.ca. Backup and log retention is separate from self-service statement deletion; no owner-approved retention schedule is currently configured.
No public security-disclosure mailbox is active yet. Before launch, Dracit must publish and verify a monitored disclosure channel. Do not send vulnerability details to an unproven address, access another user's account, exfiltrate data, run destructive tests, or attempt denial-of-service testing without written authorization.
This page describes Dracit's security posture in plain language. Formal controls, certifications, and infrastructure details should be confirmed by qualified security reviewers before launch.
See exactly how the audit works. Every dollar of missed rewards traces to a rate you can check.
How the math works