# How openfeed keeps your data safe

> Your data, protected — in plain English. What openfeed does to keep your banking and energy data secure, and how you stay in control.

- Category: security
- Audience: consumers
- Updated: 2026-07-17
- Canonical: https://openfeed.au/resources/how-openfeed-keeps-your-data-safe

---

Sharing your banking and energy data should never feel risky. openfeed is built so you stay in
control the whole time, and so your information is protected at every step.

## You never hand over your password

You connect your accounts through the Consumer Data Right — the ecosystem run by the Australian government for
sharing your own data. That means you log in with your bank or energy provider directly, and
**openfeed (and the apps you use) never see your password**.

## You choose exactly what's shared

Sharing is per account, not all-or-nothing. When an app asks for your data, you pick which
accounts it can see and confirm. Nothing is shared until you say so.

## You can turn any app off, any time

Every app you've shared with shows up in one place. Revoke any of them off instantly, and the
rest keep working. Turning off an app never breaks your bank or energy connection.

## Your data is protected behind the scenes

- Your connections use secure, encrypted sign-in, no shared passwords floating around.
- Sensitive details like card numbers are automatically redacted from your data
- Your session stays private to you and can't be read by other apps or scripts.
- All communications within the openfeed platform are encrypted in transit
- All your data is stored in encrypted form and access is cryptographically gated

## Backed by independent security standards

openfeed runs on infrastructure operated by Biza Pty Ltd, which is independently assured to a variety
of business assurance standards (**ISO 27001**,  **SOC 2 Type 2**, **ASAE3150**), is an Accredited Data Recipient
within the Consumer Data Right. All security interactions within the openfeed platform meet the 
[**FAPI 2.0** security profile](https://openid.net/specs/fapi-security-profile-2_0-final.html) and meet
the [Best Current Practice for OAuth 2.0 Security](https://datatracker.ietf.org/doc/html/rfc9700). 

In short: our systems, processes and security are **_externally verified_**, not just claimed.
