Linking a bank account to a brokerage account is safe for most people. Federal law caps what you can lose from unauthorized transfers, the data moving between the two institutions is encrypted, and deposit and investment insurance sit behind both sides of the connection. The catch is that those protections depend on you noticing problems quickly and reporting them within specific windows.
What Actually Gets Shared When You Link
Your bank password almost never travels directly to the brokerage. A third-party aggregator such as Plaid or Yodlee sits between the two, using encrypted tokens as stand-ins for your credentials. The brokerage sees your account and routing numbers, your balance, and your transaction history. It does not store your banking password.
Traffic between the institutions is encrypted, typically with 256-bit AES, the same grade the federal government uses for classified information. On top of that, nearly every bank and brokerage requires multi-factor authentication, so a stolen password alone will not get someone in. Biometric logins like Face ID and fingerprint readers meet the FIDO2 standard, which pairs your biometric with a unique cryptographic key stored on your device and is harder to spoof than a text-message code.
Brokerages also require the bank account you link to belong to you. You’ll verify ownership during setup, and firms must run customer identification programs under anti-money-laundering rules to confirm the identity of each customer.1FINRA.org. Anti-Money Laundering (AML) You cannot link a friend’s or relative’s bank account. The name match is itself a safety feature: it stops someone from draining a stranger’s account through a fake brokerage link.
What Federal Law Refunds if Money Disappears
If an unauthorized transfer pulls money out of your linked bank account, the Electronic Fund Transfer Act and Regulation E cap how much you can lose, provided you report the problem in time.2Cornell Law Institute. Electronic Funds Transfer Act Timing is everything.
- Report within two business days of learning about a lost or compromised access device and your liability tops out at $50.3eCFR. 12 CFR 1005.6 Liability of Consumer for Unauthorized Transfers
- Miss that window but report within 60 days of the statement and your exposure rises to $500.3eCFR. 12 CFR 1005.6 Liability of Consumer for Unauthorized Transfers
- If an unauthorized transfer appears on your bank statement and you don’t report it within 60 days of the statement date, there is no cap. You can lose everything the thief takes after that window closes.3eCFR. 12 CFR 1005.6 Liability of Consumer for Unauthorized Transfers
Once you file a report, your bank has 10 business days to investigate and give you a result. It can extend the investigation to 45 days, but only if it provisionally credits your account with the disputed amount within the first 10 days.4eCFR. 12 CFR 1005.11 Procedures for Resolving Errors One wrinkle: that provisional-credit requirement has an exception for accounts subject to securities margin rules, so a brokerage holding your cash under a margin agreement may not be required to give you provisional credit while it investigates.
Business Accounts Fall Outside These Rules
Regulation E only protects accounts established primarily for personal, family, or household purposes, and only for natural persons.5Consumer Financial Protection Bureau. 12 CFR 1005.2 Definitions If you link a business bank account to a brokerage, the liability caps above do not apply. You’d be relying entirely on your bank’s individual fraud policies and whatever the brokerage offers voluntarily. Read both institutions’ terms before you connect a business account.
What Insurance Covers if an Institution Fails
The liability rules deal with unauthorized transfers. Separate insurance covers the money itself if an institution collapses.
On the bank side, the FDIC insures deposits up to $250,000 per depositor, per insured bank, for each ownership category.6FDIC.gov. Understanding Deposit Insurance FDIC insurance does not cover investment losses from market moves.
On the brokerage side, the Securities Investor Protection Corporation steps in if a brokerage firm fails and cannot return client assets. SIPC coverage goes up to $500,000 per customer, with a $250,000 sub-limit for cash held at the brokerage.7Securities Investor Protection Corporation. What SIPC Protects SIPC covers custody, meaning the brokerage lost or cannot locate your stocks and cash. It does not reimburse you because a stock you owned dropped in value. Cash sitting at a brokerage is not automatically FDIC-insured, though many firms sweep uninvested cash into partner banks that carry their own FDIC coverage; check your brokerage’s sweep disclosure for the details.
Choosing How to Verify the Connection
To connect a bank account you’ll need your bank’s nine-digit routing number and your individual account number, plus whether it’s a checking or savings account. From there, brokerages usually offer two verification paths.
- Instant verification. You enter your bank login through a secure portal run by an aggregator like Plaid, which confirms ownership in real time. Faster, but it involves your bank username and password passing through the aggregator’s system.
- Micro-deposit verification. The brokerage sends two small deposits, typically a few cents, to your bank account. Once they appear (usually within one to three business days), you log back into the brokerage and confirm the exact amounts. No login credentials are shared, but it takes longer.
Where the Real Weak Points Are
The security architecture is strong; the privacy picture is more mixed. Aggregators can collect more data than users expect. Plaid faced a class-action settlement in 2022 over allegations that it wasn’t transparent enough about its role and pulled more data than users realized. As part of the settlement Plaid agreed to clearer disclosures and data-minimization practices.
The more common failure point is password reuse. If your bank password is the same one you use on some retail site, a breach there hands attackers a working bank login. The aggregator and brokerage can be flawless and you’d still be compromised. Use a unique password for every financial account, and turn on multi-factor authentication everywhere it’s offered.
Unlinking an Account and Revoking Aggregator Access
If you close a brokerage account or just want to sever the connection, unlink the bank account through the brokerage’s settings first. That may not cut off the aggregator’s access on its own. If you linked through Plaid, log in to the Plaid Portal, select the app you want to disconnect, and remove the connection. That stops future data access but may not delete data the app already stored, so contact the brokerage’s support team separately if you want stored data purged. Most other aggregators offer similar portals or support channels.
Habits That Keep the Protections Working
Every federal liability protection above hinges on how fast you spot and report a problem. Someone who reviews transactions weekly and catches an unauthorized transfer the day it posts is in vastly better shape than someone who opens statements once a quarter.
A few habits do most of the work. Check your bank and brokerage statements often. Use a unique password on each account and enable multi-factor authentication, ideally with biometrics rather than text codes. Avoid logging into financial platforms on public Wi-Fi without a VPN. Keep your phone number and email current at both institutions so alerts and verification codes actually reach you.
If a transfer you didn’t authorize shows up, report it to your bank within two business days. Don’t wait to see if it resolves itself. The clock starts the moment you become aware of the problem, and the gap between a $50 loss and an uncapped one is how quickly you make the call.