Skip to content
otto
Open Finance

Is Open Finance safe? Real risks and how to protect yourself

Is Open Finance Brasil safe? See its layers of protection, the real risks, how to spot fake consent screens and a checklist for connecting your account calmly.

Otto TeamUpdated 9 min read

Quick answer

Open Finance Brasil is safe by design, because it requires consent inside your own bank's app, never passes on your password, limits data and time, and only admits institutions authorized by the Central Bank. No system is risk-free, though, and the main danger is scams that imitate authorization screens to steal passwords or trick you into payments.

Key takeaways

  • Open Finance security comes from several layers, not just one
  • Your bank password is never given to the app receiving the data
  • The biggest real risk is scams imitating the consent screen, not the technology itself
  • Legitimate authorization always happens inside your bank's official app
  • Review and cancel consents you no longer use
In this article
  1. The short answer: safe by design, not foolproof
  2. The layers of protection in Open Finance
  3. The real risks, honestly
  4. How to recognize a fake screen
  5. Open Finance vs other ways of giving access
  6. A concrete scenario: what is at stake
  7. What to do if you suspect something
  8. Checklist before connecting your account
  9. How Otto handles security
  10. Official sources and further reading
  11. Frequently asked questions

"I am going to give an app access to my bank account? What if it leaks?" That suspicion is healthy. Money is sensitive, and every month brings news of a new scam. Before connecting anything to your bank, it makes sense to understand what is protecting you and what is not.

The short answer is that Open Finance Brasil was designed to be safer than the alternatives that existed before. The honest answer is that no system is risk-free, and the weakest link is usually a scam that tries to fool the person, not the technology.

In this guide you will see the layers of protection in Open Finance, the risks that really exist, how to recognize a fake screen, what to do if something goes wrong and a checklist for connecting your account with peace of mind.

The short answer: safe by design, not foolproof

Open Finance Brasil is regulated by Banco Central do Brasil, the country's central bank, and by the National Monetary Council (CMN). That means mandatory participation rules, common technical standards and supervision. It is not an informal agreement between companies.

Being "safe by design" means the system was built to limit damage even when something fails. Your data is not open to just anyone. Each access is authorized by you, with a defined scope and time limit, and travels through encrypted channels between authorized institutions.

But security is not an on-off switch. It is a sum of layers. Understanding each one helps you see where the risk really lies.

The layers of protection in Open Finance

LayerHow it worksWhat it protects against
Authorized participantsOnly institutions authorized by the Central Bank can joinUnknown companies receiving your data through the official channel
Consent at your bankAuthorization is confirmed in the app or internet banking of the institution holding the dataThird parties accessing your data without your knowledge
Password is not sharedYou log in at your bank, and the receiving app never sees your passwordTheft or reuse of your credentials
Limited scopeYou see and approve which data groups will be sharedBroad, unnecessary access
Defined time limitEach consent has an end date (up to 12 months under the general rule)Permanent, forgotten access
Revocation at any timeYou can cancel at your bank or in the receiving app, without giving a reasonBeing stuck with an authorization
Technical standardsCommunication through standardized APIs, with digital certificates and encryptionInterception and access by unauthorized systems
LGPDBrazil's data protection law (Law 13,709/2018) applies to the use of the dataUse of data beyond the stated purpose

Notice that no single layer solves everything. The strength is in the combination. Even if a receiving company had a problem, it would not have your password, it would only have the data you authorized, and only for a limited time.

Read-only vs payment initiation

There are two very different uses. Data sharing is read-only: the app sees your balance, statement or card bill, but cannot touch your money. Payment initiation allows an app to start a Pix payment (Pix is Brazil's instant payment system), but each payment must be approved by you in your bank's app.

If you only want to organize your finances, read-only access greatly reduces the risk. The worst case for a read-only app is exposure of information, not a withdrawal.

The real risks, honestly

Saying something is "100% safe" would be dishonest. These are the risks worth knowing:

This is the most concrete risk. Scammers can create fake websites, messages or apps that copy the look of an Open Finance authorization and ask for your password, token or a code you received by text message. If you type it in, you have handed over the keys to your account, and that has nothing to do with real Open Finance.

2. Social engineering by phone or message

Someone pretends to be a bank or app employee, says they "need to validate your Open Finance" and asks you to approve something, share a code or make a "test" Pix. No bank does this. It is the same script as the most common Pix scams in Brazil, just with a different excuse.

3. Sharing more than you need

The consent is legitimate, but you approved data groups the app does not even use, or connected a service you no longer remember. It is not an intrusion, but it increases your exposure for no reason.

4. How the receiving company uses your data

The receiving institution must use the data only for the stated purpose, following the LGPD. Even so, choose companies that clearly explain what they do, where they store data and how you can request deletion.

5. Technical failures and incidents

Institutions, systems and suppliers can fail. The design of Open Finance reduces the impact (no password, limited scope, time limit), but it does not make incidents impossible.

How to recognize a fake screen

One rule covers almost everything: legitimate authorization ends inside your bank's official app, opened from your own phone, where you log in the usual way.

Warning signs:

  • You are asked for your bank username and password on a website, form or inside an app that is not your bank's.
  • You are asked for a verification code, token or password by phone, WhatsApp or email.
  • The message arrives without you having started anything, with urgency ("your access will be blocked today").
  • The link has a strange or shortened address, or typos.
  • You are asked to make a Pix or transfer "to validate" the connection.

Open Finance vs other ways of giving access

To see why Open Finance is considered safer, compare it with the alternatives:

Type of accessWho sees your passwordScopeTime limitCancellation
Open FinanceOnly your bankData groups you chooseSet in the authorizationAt your bank or in the app, any time
Sharing your password with an app (screen scraping)The app and anyone with access to its systemsEverything you see at your bankUntil you change your passwordOnly by changing your password
Typing everything into a spreadsheet by handNobodyOnly what you typeNot applicableNot applicable

The spreadsheet is the most "closed" option, but it takes work and is often abandoned. Screen scraping is the riskiest: the app logs in as if it were you, which violates many banks' terms of use. Open Finance sits in the middle: convenience with control. If you are weighing manual tracking against an app, our guide on how to track expenses shows a routine that works either way.

A concrete scenario: what is at stake

Consider Rafael. He has R$ 3,500 in his checking account and R$ 12,000 in an emergency savings pocket at the same bank. He connects this account to a money management app.

If the connection is through Open Finance, read-only, the app can see the R$ 15,500 (3,500 + 12,000) and the statement. It cannot move a single cent. If the app had a security problem, the possible damage would be exposure of that information, which is bad, but does not empty the account.

Now imagine Rafael had fallen for a fake screen and typed in his bank password and the text message code. In that case, the scammer would have access to the bank app and could try to move the R$ 15,500, within the account's transaction limits. That is why the real danger is not in legitimate consent, but in a password handed over in the wrong place.

An extra protection that applies in both cases: Pix and transfer limits adjusted to your routine reduce the damage of any scam. In Brazil, night-time Pix (by default from 8 p.m. to 6 a.m.) is limited to R$ 1,000 for individuals unless you change it, and increases to limits take 24 to 48 hours to apply.

What to do if you suspect something

  1. Revoke the suspicious consent in the Open Finance area of your bank's app.
  2. Change your bank password if you typed it anywhere outside the official app.
  3. Call your bank on the official number (on the back of your card or in the app), never on a number you received in a message.
  4. Check statements and card bills from the last few days for strange transactions.
  5. File a police report (boletim de ocorrência) if you lost money, and ask your bank to dispute the transaction through official channels. For Pix, banks use the MED, the Central Bank's Special Return Mechanism; a refund depends on there being money left in the scammer's account, so speed matters and it is not guaranteed.

If the problem involves the company that received your data, you can exercise your LGPD rights: request access to the information, correction or deletion.

Checklist before connecting your account

  • Does the company clearly explain what it will use your data for?
  • Were you taken to your bank's official app to authorize?
  • Do the requested data groups make sense for the service?
  • Is the authorization's time limit clear?
  • Does the app request only read access, if all you want is to organize your finances?
  • Do you know where to cancel later?

If the answer is "yes" to everything, the risk is low and well controlled. If anything feels off, stop.

How Otto handles security

Otto Finanças connects your accounts through Open Finance Brasil, via the aggregator Malvo, with read-only access. It does not ask for your bank password, does not make Pix payments and does not move money. You can cancel the connection in your bank's app or in Otto. And when you use the chat with Otto, the same rule applies as with any AI tool: never type passwords or codes, as we explain in using AI for personal finance safely.

Official sources and further reading

Frequently asked questions

Can Open Finance steal my money?

Open Finance data sharing is read-only and does not allow anyone to move money. Payments through Open Finance require a different service, payment initiation, in which each transaction must be approved by you in your bank's app. The risk of losing money appears when people fall for scams that imitate authorization screens and hand over passwords or codes outside the official app.

Does the app receiving my data learn my password?

No. With Open Finance, you log in directly to your bank's app or internet banking, and the app receiving the data never sees your password. It only receives a technical authorization limited to the data and time period you approved. If an app asks for your bank username and password inside its own interface, it is not using official Open Finance.

Is Open Finance worth it, or is it better to track everything by hand?

Tracking by hand exposes less data, but it requires daily discipline and is often abandoned within a few weeks. Open Finance brings in transactions automatically, with consent, scope and time limits you control. For most people the trade-off is worth it, as long as the connection is read-only, made with a transparent company and reviewed from time to time.

How can I tell if an Open Finance screen is fake?

Be suspicious of any screen that asks for your username, bank password, token or verification code outside your bank's official app. Legitimate authorization always takes you to the app or internet banking of the institution holding your data. Urgent messages, shortened links and requests for a Pix payment to validate the connection are also clear signs of a scam.

What happens to my data if I cancel my consent?

When you revoke consent, the receiving institution stops getting new data from that moment on. Data already received follows the LGPD and the company's policy, and you can ask how it is being processed or request deletion where applicable. Revoking is quick and can be done in your bank's app or in the app receiving the data.

Otto Team

Reviewed by: Otto Finanças editorial team

We are the team building Otto Finanças, a personal and couples finance app, free to start, powered by Open Finance Brasil. Our guides are based on official sources (Central Bank of Brazil, Receita Federal, Tesouro Direto, B3, FGC) and on how people actually deal with money.

Published:
Updated:

Educational content. Not investment advice or individual guidance. Rules, rates and limits change: always check the official source before deciding.

How we create our content

Also in: Português · Español

Keep reading