Security
How we handle your financial data and how to verify Smoothy’s security status yourself
We take security very seriously, and we support you in being cautious about how your financial data is being handled. We've had to acquire official security accreditations in order to operate as a personal finance application provider, which involves testing and investigation into our technology, our employees and our processes. But you don't just have to take our word for it. This page explains how your connection to us is secured, and gives you independent tools to check it for yourself.
How we handle your financial data
We connect to your bank through New Zealand's Open Banking infrastructure, provided by Akahu. This means you give Smoothy access to read your transactions through your banking app, and we never ask for your online banking username and password. We cannot move money or make payments, and your information will never be shared with anyone else (without your permission, for example inviting another person to your Smoothy account). We do not use your data for AI training, and in fact we do not even collect personal information about you — all our access to your financial data is managed through the Open Banking connection your bank provides.
Learn more about Open Banking
Every connection is encrypted
All traffic to and from our app is protected with modern TLS encryption and a certificate issued by a publicly trusted certificate authority. In plain terms: the connection between your device and us is private, and your browser has independently confirmed our identity before any data is exchanged. Nothing we use is self-signed or untrusted.
What our certificate confirms
- Encrypted with modern TLS (currently TLS 1.3).
- Certificate issued by a publicly trusted authority (currently Google Trust Services).
- Complete, valid certificate chain that verifies without errors.
- Logged in public Certificate Transparency records, which browsers now require.
How to check our security status
There are a number of independent services, not run by us, that you can use to verify the security of the Smoothy app. These services inspect our live security certificate and report what they find, so you can confirm everything first-hand. Certificates are renewed regularly, so these links always show the current, up to date result.
- SSL Labs report — full grade, issuing authority and chain check for app.smoothyhq.com.
- SSL Labs (sign-in host) — the same independent check for our sign-in service.
- Certificate Transparency log — public, tamper-evident record of every certificate issued for our domain.
- Hardenize report — a broader overview of our encryption and email security posture.
Using a firewall or network filter?
Some network security tools can block our sign-in even though our certificate is completely valid. This happens because the tool filters by web address, not because anything is wrong with our security.
If sign-in will not load, you can allowlist (whitelist) the Smoothy app domains in your firewall settings, or exclude them from TLS inspection:
*.smoothyhq.com clerk.app.smoothyhq.com *.akahu.nz
If you have any issues or questions, contact support@smoothyhq.com
Report a security issue
If you believe you have found a security problem, we would like to hear from you. Please email security@smoothyhq.com