Skip to content
CandorHome

Is it safe to let an AI near your money?

It can be, if the boundaries are real. The safe pattern gives an AI sight without power: read-only data, logged access, and action only through you. Here is how Candor draws those lines, and what to check in any tool that wants to touch your accounts.

How it works with your agent

  1. 01Candor supplies your agent with read-only financial facts and their history.
  2. 02Your agent explains what it found and asks before anything changes.
  3. 03External actions happen through your agent's own tools, under permissions you grant it.
  4. 04Disconnect, revoke, export, and delete stay one click away the whole time.

Sight without power

The core of safe AI money management is separating seeing from acting. Candor gives your agent complete visibility: accounts, transactions, debts, holdings, history. It gives it zero ability to change anything. No money movement, no trading, no bill pay, no account changes, by architecture rather than by promise. The tools simply do not exist.

Credentials stay out of reach

You connect accounts by signing in with your bank directly, through a dedicated account-linking provider. Candor never sees your bank login, and neither does your agent. On your own machine, the CLI uses native OS credential storage by default; headless hosts must explicitly choose a user-restricted credential file.

Every read is on the record

Whenever your financial data is read, Candor logs what was requested and why. You can see how your data is being used, which turns 'trust me' into something you can actually check.

You can always leave

Safety includes the exit. You can disconnect any account, revoke any OAuth client grant, export your organized data, and delete what Candor holds. Cancellation is not a maze.

A checklist for any AI money tool

Whatever you use, ask five questions. Can it move money, and if so, what stops a mistake? Where do your bank credentials live? Are reads logged somewhere you can inspect? Can you export and delete your data completely? Is your data used to train models or sold? Candor's answers: it cannot move money, your credentials never touch it, every read is logged with a reason, export and delete are yours, and your data is never sold or trained on.

Keep reading

Keep the boundaries real.

One message to the agent you already use. You see the price before anything private, approve the access and accounts yourself, and your agent is working within minutes.