Skip to content

What we connect to

Exactly three live connections, all read-only: Stripe for SaaS revenue, RevenueCat for subscription apps, and Mercury for the bank. Statements from any other bank, and every other file, are uploads.

StripeMercuryRevenueCatread onlyAES-256-GCMEncrypted at restNo write accessBuyer's viewMRR$18,240Cash in, 90 days$41,870Active subscriptions1,284
Stripe
A restricted key (it starts with rk_live_) with Read on Balance, Charges and Refunds, Customers, Disputes, Events, Payouts, Products, Coupons, Invoices, Prices and Subscriptions. Everything else stays at None. Paste a secret key and we refuse it.
RevenueCat
A v2 secret key with read-only access to Charts & metrics (Overview and Charts), and optionally Projects to read the project name. Everything else stays at No access.
Mercury
A read-only API token, used to show cash in and out and to match payouts to deposits.

How to make a read-only Stripe key

How credentials are kept

  • Envelope encryption: each key or token gets its own AES-256-GCM data key, and that data key is wrapped by a master key kept outside the database.
  • Credentials are never written to logs. They are decrypted only inside the sync worker, at the moment it reads from the source.
  • They are deleted within 7 days of your plan ending after you cancel, or of your account being deleted. Numbers already synced stay in the room until you delete it.

Statement uploads

Upload statements from any bank as PDF or CSV. We read the transactions, using Anthropic's API for PDFs, and check that the opening balance plus the transactions equals the closing balance. We also look for tamper signals, such as a PDF saved by a word processor or image editor, or changed long after it was created. Balance checks and tamper signals are shown only to you, never to buyers. Buyers see the figures labelled “Uploaded by seller” with the upload date.

Updates by email

On the 5th of each month we email you what's live in your room and what's missing. Reply with files attached and they go into the room. We accept a reply only when it comes from the room owner's email address and is sent to that room's private address, which carries a per-room token. Anything else is discarded.

What we never store

  • Buyer passport or licence images
  • Customer card numbers
  • Full bank account or routing numbers
  • Keys that can write, refund or move money
  • Your Stripe, RevenueCat, Mercury or bank passwords

Buyer ID checks

Buyers can choose to have their ID checked with a passport or driving licence. Stripe Identity runs the check; the document and selfie stay with Stripe. We keep only the result, the name on the document, the document type and the country. Sellers see “ID checked” next to the buyer's name.

Revoking our access

Cut us off at the source any time, without asking. Numbers already synced stay in the room until you delete it; nothing new comes in.

Stripe

DevelopersthenAPI keysthenRestricted keys

Delete or roll the key you made for WarpExit.

Mercury

SettingsthenAPI tokens

Revoke the token you made for WarpExit.

RevenueCat

Project settingsthenAPI keys

Delete the secret key you made for WarpExit.

What buyers can do

Only what their stage allows. Every file view is watermarked with their email, the time and the room ID, downloads are off unless you allow them, and you can revoke one buyer without touching the rest.

jane@northpoint.example28 Sep 2026, 14:05 UTC, room frm-7f3kP&L 2025, normalizedFormly. US dollars.
Formly roomOne link per buyerJane OrtizNorthpoint CapitalMarcus LeeIndependent buyerAna PetrovaHarbor LaneTom BeckerRevoked, link closed

Audit log

Every NDA signature, stage change, download and revoke is recorded with who and when.

  1. 14:05Jane Ortiz signed the NDA
  2. 14:06You moved Jane Ortiz to stage 2
  3. 14:31Jane Ortiz downloaded P&L 2025, normalized.pdf
  4. 16:12You revoked Tom Becker
Illustration. Times in UTC; names are made up.

Deleting your data

Delete a room or your account and every buyer link stops working at once. Stored keys and tokens are deleted within 7 days. Our policy is to delete synced numbers, files and buyer activity within 30 days.

What we don't claim

WarpExit organizes numbers from your connections and uploads and labels each one with where it came from. It doesn't audit them. WarpExit holds no SOC 2 report or other security certification today. For a security questionnaire or to report a vulnerability, email mail@warplabs.co.