Security
Updated July 17, 2026 · Written in plain language; it may be revised as the product grows.
Steward signs in to portals and acts on your behalf, so its security model is built around one idea: give the agent the ability to work without ever giving it, or anyone else, your secrets.
Passwords stay out of the conversation
Portal logins go from the secure connect form straight into an encrypted vault (envelope encryption with a separate key service). When Steward signs in for you, credentials are filled into the sign-in form by reference: the browser navigator identifies the username and password fields, and the vault supplies the values. Credentials are not included in the model prompt or ordinary conversation transcript.
Verification codes stay yours
Two-factor codes are requested from you at the moment of sign-in, encrypted immediately, used once, and purged. Steward never asks you to weaken or turn off two-factor authentication.
Read-only money access
Bank and card connections are read-only, provided through our banking data partner. Steward can see charges to check them; it cannot move, send, or withdraw money.
You see what Steward is about to do
Before Steward sends a dispute, cancels a subscription, files an appeal, requests a refund, or takes another outward action, it shows you the exact action and asks you to confirm it. That confirmation is bound to what you saw, so changed content cannot run under an earlier confirmation. Steward also pauses when it needs missing information, a live verification code, or a decision only you can make.
Background checks stay read-only
While work is active, Steward may sign in to the relevant portal periodically to see whether the biller has replied. Those background sign-ins only read: they never submit, reply, or change anything. If a portal asks for a fresh verification code, Steward stops and asks you to come back rather than acting without you.
Encryption
Data is encrypted in transit (TLS) and at rest. Credential material is additionally envelope-encrypted.
Honest posture
Steward is built by a small team. We do not yet hold formal security certifications, and we will not claim ones we do not have. If you find a vulnerability, email support@heysteward.ai.