Skip to main content

Security and Data Privacy in Kerdora

Written by Taylor Stewart

Kerdora uses administrative, technical, and physical safeguards designed to protect personal information, including encryption in transit and at rest, role-based access controls, least-privilege access, administrative-system multifactor authentication, logging and monitoring, and regular security-practice reviews. Kerdora's current Privacy Policy, Trust Center, subprocessors list, Terms, and any signed Data Processing Agreement are the authoritative materials for a firm's security and vendor review.

This Help Center article explains the main privacy answers and user controls in plain language. It is not a security certification, penetration-test report, or contractual amendment.

What client and advisor data does Kerdora process?

Kerdora processes account information for advisors and firm users and the client information entered, uploaded, connected, or generated for the planning relationship. Client data can include household details, income, spending, assets, liabilities, Goals, tax information, estate information, insurance, notes, documents, connected-account data, and AI feature inputs and outputs.

Kerdora acts as a processor or service provider for end-client data on behalf of the advisor. The advisor is responsible for deciding what client data to collect, providing required notices, obtaining applicable consent, and responding to client requests with Kerdora's assistance.

The current Privacy Policy is available at go.kerdora.com/privacy-policy.

Is Kerdora data encrypted and access-controlled?

Kerdora's current Privacy Policy states that safeguards include encryption in transit using TLS, encryption at rest, role-based access controls, least-privilege access, administrative-system multifactor authentication, logging, monitoring, and regular review of subprocessors and security practices.

Each advisor and invited client should use an individual account. Advisor access follows the firm and role permissions configured in Kerdora. A client is limited to the applicable household portal and cannot access the advisor's Planning modules, Dora, Guide editor, Office, or other households.

No system is perfectly secure. Do not share logins, and remove or revoke access when a person no longer needs it. Use a password manager, protect the email account used for login and recovery, and sign out on shared devices.

Does Kerdora store bank login credentials?

No. The current Privacy Policy states that the end client enters institution credentials directly in the account aggregation provider's authentication flow; Kerdora does not see or store those institution login credentials.

The Privacy Policy currently identifies Array as Kerdora's account aggregation provider. The provider can return account names, account types, balances, holdings, positions, and transaction history to Kerdora for the connected household. A connection can be revoked, which stops future refreshes; previously retrieved data remains subject to the Privacy Policy's retention terms.

Advisors and Kerdora Support should never ask a client to put a bank password or multifactor code in a note, document, Dora prompt, email, or support message.

Does Kerdora use client financial data to train generative AI models?

No. Kerdora's current Privacy Policy states that Kerdora does not use end-client financial data to train generative AI models. It also states that AI subprocessors process inputs and outputs to provide the requested feature under contractual terms that prohibit using Kerdora customer data to train their models.

AI features are available to advisors and firm users, not end clients. Relevant client data selected for an AI-assisted request can be sent to the applicable AI subprocessor. Advisors should submit only the information needed for the task and review AI-generated outputs before relying on or sharing them.

The current Privacy Policy identifies Anthropic and Google as AI subprocessors. Use Kerdora's current subprocessors list for the authoritative vendor roster because providers can change over time.

Does Kerdora sell personal information?

No. Kerdora's current Privacy Policy states that Kerdora does not sell or rent personal information and does not share personal information for cross-context behavioral advertising.

Kerdora does use service providers and subprocessors for functions such as hosting, infrastructure, payments, analytics, customer support, communications, account aggregation, and AI processing. Data can also be shared at the advisor's direction or when required for legal, safety, compliance, or business-transfer purposes described in the Privacy Policy.

How long does Kerdora retain data?

Kerdora's current Privacy Policy states that account and client data is retained while the advisor's account is active and for a reasonable period after termination for export, dispute resolution, and legal compliance. Billing records, backups, logs, aggregated data, and other records can follow different schedules or legal requirements.

The Terms state that a customer has 30 days after termination to export Customer Data, after which Kerdora may delete it subject to legal requirements and backup schedules. Because retention obligations can depend on the record and contract, use the current Privacy Policy, Terms, and any signed DPA for a formal review instead of relying on a remembered Help Center number.

What can an advisor control inside Kerdora?

An advisor can reduce unnecessary exposure through the product workflow:

  • verify the adult and email before sending a portal invitation;

  • use individual user accounts instead of shared credentials;

  • remove or revoke access that is no longer needed;

  • review which Guides are client-visible;

  • review whether a Change or Task is assigned to the client;

  • verify document visibility before relying on the portal for delivery;

  • upload only records needed for the planning relationship;

  • avoid unnecessary full account numbers and sensitive identifiers in notes and prompts; and

  • review AI extraction proposals and Dora proposals before applying data changes.

Use the client portal or another firm-approved secure workflow instead of ordinary email when exchanging sensitive financial documents.

Where can my firm get security and compliance documentation?

Use Kerdora's current Trust Center for available security materials and the current subprocessors list. A Data Processing Agreement is available on request where needed, as described in the Terms.

Older Help Center copy may name MoneyKit or quote implementation details such as a password algorithm, session duration, database product, or upload size. Do not use those older statements for a current vendor review. The April 28, 2026 Privacy Policy identifies Array for account aggregation and provides the current public security and privacy commitments.

For a vendor questionnaire or contractual review, request the current materials instead of inferring infrastructure, certifications, audit results, retention, or incident-response commitments from the product interface. The Privacy Policy and Terms were last updated April 28, 2026 at the time this article was reviewed.

What should I do if I suspect unauthorized access or data exposure?

Report a suspected incident promptly. Preserve the approximate time, user, household, affected records, visible behavior, device or browser context, and any relevant screenshots. Do not send passwords, multifactor codes, or full account numbers in the report.

The current Privacy Policy directs privacy and security reports to taylor@kerdora.com. Advisors can also use the approved Kerdora support channel. If an advisor believes an email account, device, or external institution was compromised, the advisor should also follow the firm's incident-response procedures and contact the applicable provider.

What does this Help Center article not prove?

This article does not claim a certification, audit opinion, penetration-test result, recovery objective, fixed backup interval, guaranteed breach-prevention outcome, or contract term. Those details require current authoritative documentation and, where applicable, a signed agreement.

For the controlling terms and the most current details, use the Kerdora Privacy Policy, Terms of Service, Trust Center, subprocessors list, and any agreement signed with the firm.

Did this answer your question?