← Back to site

Data & Security

Last updated 1 August 2026 · Holmes AI, Inc.

The short version

Your money never moves through Artho. Bank access, when you grant it, is read-only. Documents you upload are thrown away after answering unless you say to keep them.

We are an early-stage company and we would rather tell you what we have not built yet than imply a maturity we do not have. That list is at the bottom of this page.

Your money never moves

Artho has no ability to initiate a payment, transfer, or trade. There is no code path for it. When you connect a bank through Plaid, the permission granted is read-only: Artho can see that a transaction happened, and nothing more. Your banking credentials go to Plaid and are never received or stored by us.

How your data is separated

Every row of your data — profile, conversations, documents — is tagged with your user ID and protected by row-level security enforced by the database itself, not by application code. A query made on behalf of one account physically cannot return another account's rows, even if the application above it has a bug.

Uploaded files live in a private bucket. There are no public URLs. A file is reachable only through a short-lived link issued to the account that owns it.

Encryption

What is off by default

Two things that other products tend to switch on for you:

You can see exactly what Artho has learned about you, and erase it, from your account page.

We do not sell your data

Not to advertisers, not to data brokers, not to anyone. It is not a revenue line we have, and not one we intend to add. Our subprocessors are listed in full in the Privacy Policy, including which country each one operates in.

Where answers are generated

Artho's answers are written by a large language model operated by DeepSeek, whose infrastructure is in China. Your question, and any document text needed to answer it, is sent there for processing. We think you should know that before you upload a bank statement. It is stated plainly in the Privacy Policy as well.

Reporting a vulnerability

If you find a security problem, email security@artho.ai. Please give us a reasonable chance to fix it before publishing. We will acknowledge your report, keep you updated, and credit you if you would like that. We will not pursue legal action against good-faith research that respects user privacy and does not degrade the service.

What we have not built yet. Artho is pre-launch and we would rather be straight with you than imply otherwise. We do not currently hold a SOC 2 or ISO 27001 certification. We do not yet offer two-factor authentication or a paid bug-bounty programme. We have not undergone an independent penetration test. These are on the roadmap before general availability; until they are done, this page will keep saying so.

Holmes AI, Inc. · security@artho.ai