Credential flow
Quiltt is never in the credential flow
We do not receive, process, or store your end users' bank credentials.
When a user connects an account, Quiltt renders a single institution search across every provider you've enabled. Once the user selects their bank, authentication happens with the institution or the underlying aggregator directly:
Direct bank OAuth:
The user is handed off to their bank's own site or mobile app and authenticates there. Credentials never leave the bank's domain.
Aggregator-hosted flow:
Where a bank offers no OAuth endpoint, credentials are entered into the aggregator's own hosted interface.
In neither path does a credential pass through Quiltt infrastructure. This is a structural property of the integration, not a policy we enforce on ourselves — there is no code path in which we hold one.
Source: Fathom — Natansh Bhamba call, 2026-06-10, 00:06.

