Modern Corporate Treasury, Cash Yield & Banking ArchitecturePlaybook3 min readUpdated September 2026

Plaid vs Direct Host-to-Host: How Your Bank Feed Actually Gets to Your Software

Your bank feed reaches your software either through an API aggregator such as Plaid or through a direct host-to-host connection, usually SFTP, and the two differ in latency, credential handling and control. Most software vendors pick one and present it as a connect-your-bank button, but it matters once a security review or diligence request asks which you're on.

Most finance teams never choose between these directly, since the software vendor usually picks one and presents it as a simple connect-your-bank button. It's still worth understanding which one you're on, particularly once a security review, a diligence request, or a larger bank relationship makes the underlying mechanism someone's actual question.

Vendors Covered in this Article

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

How an API Aggregator Like Plaid Actually Works

Where a bank supports it, you authenticate directly with your own bank through an interface the bank controls, and the aggregator receives a token rather than your actual password. Where a bank hasn't built that kind of connection, some aggregators still rely on stored credentials behind the scenes to pull data on your behalf, which is a meaningfully different risk profile even though the end result looks identical in your software. Refresh timing also varies: some connections update close to real time through a webhook, while others refresh on a periodic schedule that can lag by hours.

How a Host-to-Host SFTP Connection Works Instead

A host-to-host connection is a scheduled file transfer, typically set up directly with your bank's treasury services team rather than through a consumer-facing connect flow. Files move on a set schedule, often once or twice a day, encrypted in transit and frequently using a separate encryption layer on the file itself. There's no real-time refresh here by design; you're trading immediacy for a connection that your own IT team can configure, monitor, and control end to end.

The Real Difference Is Latency and Control, Not Just Security

It's tempting to assume one of these two approaches is inherently more secure than the other, but that's not really the distinguishing factor. The real tradeoff is latency, an API connection can approach real time where the bank supports it, while a batch file always waits for its next scheduled delivery, and control, a host-to-host setup usually sits under your own team's keys and configuration, while an aggregator connection depends on that aggregator's own security practices and incident history.

What to Actually Ask About Encryption and Credential Storage

Ask your vendor directly whether your specific bank connects through token-based authentication or a stored-credential method, since the answer can differ bank by bank even within the same software product. Ask how data is encrypted both at rest and in transit, and ask what happens to your historical data if you ever disconnect the integration: is it deleted promptly, or retained indefinitely on the vendor's side. These are reasonable questions for any vendor to answer clearly, and hesitation to answer them plainly is itself worth noting.

Put these questions to your software vendor:

  • Does your specific bank connect through token-based authentication or a stored-credential method, since the answer can differ bank by bank?
  • How is your bank data encrypted both at rest on the vendor's systems and in transit between the systems?
  • What happens to your historical data if you ever disconnect the integration?
  • How often does the feed actually refresh for your bank, given that near real time can mean hourly in practice?

Which One You Actually Want

If you need broad reach across many banking relationships with a fast setup, an aggregator is usually the practical choice, and it's what most small business software defaults to for exactly that reason. If you have a small number of large bank relationships and a genuine security or compliance requirement to control the connection directly, a host-to-host setup is worth the extra implementation effort, even though it takes longer to stand up and typically needs your bank's treasury services team involved from the start.

What This Looks Like as You Grow Past Your First Setup

A company that started with an aggregator connection because it was fast to implement doesn't have to rip it out the moment it adds a bigger bank relationship or a compliance requirement. Many treasury and accounting platforms support both connection types side by side, so you can move your highest-volume or most sensitive accounts to a host-to-host connection while leaving smaller, lower-risk accounts on the aggregator feed. Reassess this mix whenever you add a new bank relationship rather than assuming your original setup still fits every account equally well.

This is also worth revisiting the first time a customer, auditor, or investor asks a specific question about how your bank data moves. Having a clear, current answer ready, rather than needing to go find out, is usually a better use of the review than waiting for the question to force it.

Executive Capability Standard

What Good Looks Like

Good bank connectivity governance means knowing, for every account connected to any piece of software, whether it's an API or host-to-host connection, how credentials are handled, and how often the data actually refreshes.

Building The Capability (5-Stage Skill Ladder)

1. Learn:List every software tool with a live bank feed connection and identify, for each one, whether it uses an API aggregator or a direct host-to-host connection.
2. Do Manually:Ask each vendor directly how your specific bank's connection is authenticated and how often it refreshes, rather than relying on general marketing claims.
3. Delegate:Have whoever owns your security or vendor review process add bank connectivity questions to your standard vendor questionnaire if they aren't already there.
4. Automate:Where your bank supports it, confirm your connections use token-based authentication rather than stored credentials, since this removes an entire category of risk automatically.
5. Buy:Bring in a security reviewer to audit your bank connectivity setup before a compliance review, rather than discovering gaps during the audit itself.

How to Get Started

Disclosure: We may earn a commission if you buy through some links on this page. It doesn't change what we recommend.

BILL

BILL relies on a live bank feed connection for reconciliation, so it's worth confirming with them directly which connection method applies to your specific bank.

Visit BILL→

Frequently Asked Questions

Does Plaid ever see our actual bank password?

It depends on the bank. Where a bank offers a direct authentication connection, you authenticate with your bank and the aggregator never sees or stores your password, only a token the bank issues. Where a bank hasn't built that connection yet, some aggregators still use a credential-based method behind the scenes, so ask your specific software vendor which method applies to your specific bank rather than assuming one universal answer.

Is a host-to-host SFTP connection actually more secure than an API connection?

Not automatically. Security depends on how well either connection is configured, key rotation, encryption standards, and monitoring, not on which category it falls into. A well-configured API connection using bank-level authentication can be just as secure as a poorly maintained file transfer setup, and the reverse is equally true, so ask about the specific implementation rather than assuming the category alone answers the question.

How often does an aggregator-based feed actually refresh?

This varies by aggregator and by bank, and near real time in marketing language sometimes means refreshed hourly or on a webhook trigger rather than truly instant. If same-day accuracy matters for a specific decision, confirm the actual refresh cadence for your specific bank connection rather than assuming it matches whatever the software's homepage implies.

About the numbers

This guide doesn't quote a sourced benchmark. Figures in it are estimates or general guidance, so check them against your own numbers.

Related Guides