Trust is not a marketing word here.

This page exists so you can decide whether to give Wade.Tech access to anything sensitive in your life — your bank, your home, your calls. Every claim here is something we hold ourselves to in code, in policy, and in audit.

The lock on a door isn't decoration. Neither is this page. Every claim below is something we hold ourselves to in code, in policy, and in audit.

trust · live posture

Three things we will never do with your data.

No passwords. No account numbers.

Plaid's read-only tokens. We never see what you type.

scope: read-only

Read only. Never move.

Our software cannot move money or send anything in your name.

writes: 0

Isolated. Encrypted. Yours.

Walled off per person. No casual review. No partners.

tenant-isolated

What we collect, and do not

We collect

  • Bank transaction data (via Plaid read-only tokens)
  • Account types and balances you've opted to sync
  • The information you give Higgins (face/voice recognition data — local on your device)
  • Your travel route searches (for the watch feature, if you opt in)
  • Site analytics (page views, anonymized, GA4)

We do not collect

  • Bank passwords or login credentials (Plaid handles these — we never see them)
  • Card numbers or CVVs
  • Continuous home audio/video (Higgins listens/watches for what you asked)
  • Your contacts list, location history, or microphone outside Higgins-specific use

How bank connections work

Plaid is the financial-data gateway. You log in to your bank inside Plaid's secure flow — Plaid issues a token to Wade.Tech. The token can read transactions but cannot move money, change account settings, or initiate transfers. We can revoke our access; you can revoke our access; nothing happens to your money without you triggering it on your bank's side.

How AI conversations are handled

When a product uses Aspen to think, your prompt is sent to an intelligence provider. We strip personally-identifiable information before transmission. We never retain prompt content in long-term storage. We do retain routing metadata (what kind of question, what tier responded, latency) for analytics on what works — without the words.

Multi-tenant isolation

Every customer's data lives behind a tenant boundary. No cross-tenant queries are possible in the data layer. Aggregated public-website data (the live counters you see on this site) is gated to cohorts of 5+ tenants so no individual can be inferred.

Encryption posture

At rest: AES-256 on databases and backups. In transit: TLS 1.3 only. Keys: AWS KMS with rotation; access logged.

Auditing & accountability

Internal review monthly. We are working toward annual third-party SOC 2 Type II audit (in progress). Any security incident is disclosed to affected users within 72 hours.

Your rights

Export everything we have on you, anytime. Delete everything we have on you, anytime. Correct anything that is wrong. Email privacy@wade.technology and we respond within 5 business days.

Contact for security questions

Security questions or responsible disclosure: security@wade.technology. We honor responsible disclosure and acknowledge within 48 hours.