Read-only access, and you can revoke it any time
What we connect to
Exactly three live connections, all read-only: Stripe for SaaS revenue, RevenueCat for subscription apps, and Mercury for the bank. Statements from any other bank, and every other file, are uploads.
- Stripe
- A restricted key (it starts with
rk_live_) with Read on Balance, Charges and Refunds, Customers, Disputes, Events, Payouts, Products, Coupons, Invoices, Prices and Subscriptions. Everything else stays at None. Paste a secret key and we refuse it. - RevenueCat
- A v2 secret key with read-only access to Charts & metrics (Overview and Charts), and optionally Projects to read the project name. Everything else stays at No access.
- Mercury
- A read-only API token, used to show cash in and out and to match payouts to deposits.
How credentials are kept
- Envelope encryption: each key or token gets its own AES-256-GCM data key, and that data key is wrapped by a master key kept outside the database.
- Credentials are never written to logs. They are decrypted only inside the sync worker, at the moment it reads from the source.
- They are deleted within 7 days of your plan ending after you cancel, or of your account being deleted. Numbers already synced stay in the room until you delete it.
Statement uploads
Upload statements from any bank as PDF or CSV. We read the transactions, using Anthropic's API for PDFs, and check that the opening balance plus the transactions equals the closing balance. We also look for tamper signals, such as a PDF saved by a word processor or image editor, or changed long after it was created. Balance checks and tamper signals are shown only to you, never to buyers. Buyers see the figures labelled “Uploaded by seller” with the upload date.
Updates by email
On the 5th of each month we email you what's live in your room and what's missing. Reply with files attached and they go into the room. We accept a reply only when it comes from the room owner's email address and is sent to that room's private address, which carries a per-room token. Anything else is discarded.
What we never store
- Buyer passport or licence images
- Customer card numbers
- Full bank account or routing numbers
- Keys that can write, refund or move money
- Your Stripe, RevenueCat, Mercury or bank passwords
Buyer ID checks
Buyers can choose to have their ID checked with a passport or driving licence. Stripe Identity runs the check; the document and selfie stay with Stripe. We keep only the result, the name on the document, the document type and the country. Sellers see “ID checked” next to the buyer's name.
Revoking our access
Cut us off at the source any time, without asking. Numbers already synced stay in the room until you delete it; nothing new comes in.
- Stripe
DevelopersthenAPI keysthenRestricted keys
Delete or roll the key you made for WarpExit.
- Mercury
SettingsthenAPI tokens
Revoke the token you made for WarpExit.
- RevenueCat
Project settingsthenAPI keys
Delete the secret key you made for WarpExit.
What buyers can do
Only what their stage allows. Every file view is watermarked with their email, the time and the room ID, downloads are off unless you allow them, and you can revoke one buyer without touching the rest.
Audit log
Every NDA signature, stage change, download and revoke is recorded with who and when.
- 14:05Jane Ortiz signed the NDA
- 14:06You moved Jane Ortiz to stage 2
- 14:31Jane Ortiz downloaded P&L 2025, normalized.pdf
- 16:12You revoked Tom Becker
Deleting your data
Delete a room or your account and every buyer link stops working at once. Stored keys and tokens are deleted within 7 days. Our policy is to delete synced numbers, files and buyer activity within 30 days.
What we don't claim
WarpExit organizes numbers from your connections and uploads and labels each one with where it came from. It doesn't audit them. WarpExit holds no SOC 2 report or other security certification today. For a security questionnaire or to report a vulnerability, email mail@warplabs.co.