Mora Security

Read-Only Bank Connection Security: Why Mora Can't Move Money

Mora uses read-only bank connections — it can see your balance and transactions, but it has zero technical ability to transfer money or make payments.

The most important security feature of any finance app is the one that prevents it from moving your money. Mora uses read-only bank connections, which means the app can pull your transaction history and account balance, but it cannot initiate transfers, pay bills, or change any settings inside your bank account.

Read-only access is enforced at the protocol level by Plaid, the infrastructure layer that connects Mora to your bank. When you link an account, Plaid requests a token that grants permission to read data but not to write or modify anything. That token is the only credential Mora receives — it never gets your full account number, routing number, or the ability to authenticate as you.

How Read-Only Access Works

When you link a bank account through Plaid, your bank issues an access token that specifies exactly what the app can do. Mora requests read-only permissions, which typically include transaction history, current balance, account type, and basic account details (last four digits, institution name).

The token does not grant permission to initiate ACH transfers, wire money, pay bills, or modify account settings. If Mora tried to use the token to move money, the bank would reject the request because the token lacks the necessary permissions.

What Mora Can See

Mora can see every transaction that appears in your bank's online transaction history, usually going back 24 months. That includes the date, amount, merchant name, and category (if your bank provides one). Mora also sees your current balance and any pending transactions that have not yet cleared.

Mora cannot see your full account number, your routing number, your PIN, or any credentials you use to log in to your bank. Those details are managed by Plaid and are never passed to Mora.

What Mora Cannot Do

Mora cannot move money between accounts, even accounts you own. It cannot pay bills, set up automatic transfers, or modify direct deposit instructions. It cannot change your address, phone number, or any other account settings. It cannot close your account or request a new debit card.

If someone gained access to your Mora account — through a stolen phone, a compromised password, or a phishing attack — they could see your spending history, but they could not transfer money out of your checking account. That limitation is built into the access token and cannot be bypassed by the app.

Why Read-Only Access Matters

Traditional online banking gives you full control over your account: you can view balances, move money, pay bills, and change settings. That flexibility is useful, but it also means a compromised session can do real financial damage.

Read-only access eliminates that risk. Even if an attacker gets into Mora, the worst they can do is see your transaction history. They cannot drain your account, pay themselves, or lock you out. The financial impact of a Mora breach is limited to privacy, not theft.

Comparing Read-Only to Full Access

Some finance apps request full access to your bank account so they can offer features like automatic bill pay, peer-to-peer transfers, or savings round-ups. Those features are convenient, but they require the app to hold credentials that can move money.

Mora does not offer those features because they would require write access. The trade-off is intentional: Mora prioritizes security over convenience. If you want an app that can pay your bills automatically, you need to accept the risk that comes with granting write access.

How Banks Enforce Read-Only Access

Banks enforce read-only access by issuing tokens with limited scope. When Plaid requests access on behalf of Mora, the bank checks what permissions Plaid is asking for and issues a token that grants only those permissions.

If Mora tried to use the token to initiate a transfer, the bank's API would return an error: 'Insufficient permissions.' The token cannot be upgraded or modified after it is issued — Mora would need to request a new token with broader permissions, which would require you to re-authenticate and approve the new scope.

Token Expiration and Renewal

Most banks issue tokens that expire after 90 days. When a token expires, Plaid must re-authenticate you with your bank to get a new token. That expiration limits the window of risk if a token is stolen — an attacker would have at most 90 days of read-only access before the token stops working.

Mora handles token renewal automatically. If your bank requires re-authentication, Mora prompts you to log in again through Plaid. You do not need to unlink and re-link your account — Plaid manages the renewal in the background.

What Happens If Plaid Is Compromised?

If Plaid's systems were breached and tokens were stolen, an attacker would gain read-only access to transaction history for the duration of the token's validity (usually 90 days). They could not move money, because the tokens lack write permissions.

Plaid monitors for unusual activity and can revoke tokens remotely if a breach is detected. Banks can also revoke tokens on their end if they suspect fraud. That layered defense means even a successful attack on Plaid would have limited financial impact.

Revoking Access

You can revoke Mora's access to your bank account at any time by unlinking the account inside the app. That tells Plaid to delete the token, and Mora stops syncing your transactions. You can also revoke access through your bank's online security settings, which invalidates the token without requiring you to open Mora.

Read-Only Access and Privacy

Read-only access protects you from financial theft, but it does not protect your privacy if someone gains access to your Mora account. An attacker who logs in as you can see your full transaction history, which may reveal sensitive information about your spending, location, and habits.

That is why Mora supports two-factor authentication, biometric login, and automatic session timeouts. Those features protect your Mora account from unauthorized access, which in turn protects your transaction history from being viewed.

Should You Link All Your Accounts?

Because Mora uses read-only access, the financial risk of linking an account is near zero. The privacy risk depends on how sensitive your transaction history is and how confident you are in your ability to secure your Mora account.

If you use a strong password, enable two-factor authentication, and keep your phone locked, the privacy risk is low. If you share your phone with others or use a weak password, you may want to link only accounts that do not contain sensitive transactions.

How Mora Compares to Manual Entry

Some people avoid linking accounts entirely and enter transactions manually. That approach eliminates the risk of a compromised token, but it also means you lose automatic syncing, real-time balances, and AI-powered categorization.

Manual entry is more secure in theory, but in practice it is less reliable — people forget to log transactions, round amounts, and give up after a few weeks. Read-only access through Plaid offers a better balance: near-zero financial risk with the convenience of automatic syncing.

Get the Complete Security Checklist

Download our 12-point checklist for evaluating any finance app's security — plus a side-by-side comparison of Mora, Plaid, and traditional banking security.

No spam, ever. Unsubscribe anytime.