Orbiq

← Trust & governance

Vendor Risk Assessment — Plaid

The review of the bank-connection provider used for Canada and the US, including how the access token is protected and what happens to it when you disconnect.

Version
Approved (with mitigations)
Effective
June 1, 2026
Compliance mapping
CSA STAR STA

Download as PDF

Published with a small redaction set applied — a neighbourhood-level address, an internal contact alias, and the names of infrastructure components whose exposure would help an attacker. Nothing about what we do with your data is removed.

Vendor Risk Assessment: Plaid Inc.

Vendor Name: Plaid Inc.

Service Provided: Consumer-permissioned bank account aggregation (account metadata, balances, and transaction sync) for the Orbiq Connect tier.

Assessment Date: June 1, 2026

Status: Approved (with mitigations)

1. Data Processing Context

2. Technical Safeguards

3. Contractual & Regulatory Controls

4. Residual Risk & Mitigations

Risk FactorAssessmentOrbiq Mitigation
Cross-border (US) processingData leaves Canada; US CLOUD Act exposureDPA + SCCs; consumer disclosure & consent; region gate to US/CA
Access-token compromiseToken enables read of bank dataFernet encryption at rest, key in Secret Manager, never logged; revoke + /item/remove on incident
Webhook spoofingForged sync triggersES256 JWT verify + body hash + freshness + idempotency
Orphaned live items (cost + exposure)Items for lapsed/non-entitled usersAutomated reaper: /item/remove + token deletion on downgrade/lapse/idle

5. Continuous Oversight Plan