I used to work at a startup which did the same thing for health records. In fact, our frontend plugin was also called "Connect". As an end user, it sounds like you will take my credentials for my utility provider, log into their website with those credentials, extract my data, store it in a normalized form in your DB, and expose it through your REST API. Is this true? If so, while you are logged in, you will also hav…
Do they actually? My provider only lets me edit those details (with a low quality preview of first 4 digits and a CC icon). Interesting that yours makes those visible to you. You literally can't get those out of my provider. The data doesn't make it out.
- Am I behind on my power bills? By how much?
- How many credit cards do I have on file and how many are expired?
Such information is still sensitive even if it doesn't leak full credit card numbers.
Also, anyone who has ever used City of Palo Alto Utilities should probably fear for their credit card information.