Safety at Brev · 04

Safety at Brev

01

What exists today

Joining the Brev campus waitlist measures verified interest at a school. It does not open an account, move money, reserve a financial product, or require a deposit.

Public app screens show the direction of the product and are illustrative. Payment, yield, and investing features depend on licensed partners and may change or never launch.

  • No bank account or card number is requested during campus early access
  • No payment is required to join or keep a place on the waitlist
  • A campus entry counts only after school-email verification and the private intake are complete
02

How campus access is protected

The sign-in flow limits how long emailed links and browser challenges can be used.

  1. Verify a school email

    The emailed verification link expires after 30 minutes. Opening the page does not consume it; explicitly continuing exchanges it once for a separate intake or campus-pass session.

  2. Keep the campus pass private

    Email and session tokens are stored as hashes. The signed-in campus pass uses an HttpOnly session cookie that page scripts cannot read and that expires after 30 days.

  3. Add an optional passkey

    A passkey challenge expires after 5 minutes. Brev stores the public credential needed to verify a signed response, not the private key or biometric used to unlock it.

  4. Protect the recovery email

    Email remains the recovery method. A passkey makes ordinary sign-in harder to phish, but keeping the school email secure still matters.

03

What the waitlist collects

Brev uses waitlist information to verify campus eligibility, prevent duplicate or automated signups, run campus invites, maintain the campus pass, and understand which pages work. The waitlist notice explains retention and deletion choices in detail.

StageInformation usedBoundary
School verificationSchool email, matched domain, request and completion timesNo school password or mailbox access
Private intakeFull name, mobile number, date of birth, school confirmation, terms acceptanceNo street address, government ID, Social Security number, bank details, or card number
Campus passInvite code, verified-friend count, session record, and optional public passkey credentialNo passkey private key or biometric data
Site operationPages viewed, browser and device type, and approximate location derived from IPBrev says it does not sell personal information or share it with advertisers for their own marketing
04

How to recognize a suspicious message

  • A current campus waitlist message should never require a deposit, wire transfer, cryptocurrency, or gift card to secure access
  • Do not send a password, bank login, card number, government ID, passkey private key, or biometric data in response to a message
  • Do not share a school-email verification link; it is intended only for the mailbox that requested it
  • If a message feels unexpected, type heybrev.com into the browser yourself and contact support@heybrev.com instead of using the message’s links
  • A lookalike sender name is not proof that a message came from Brev
05

Before money features can launch

Brev is a brand of Gus AI, Inc., a financial technology company, not a bank, broker-dealer, or investment adviser. If payment, cash-sweep, card, or investing features become available, the relevant licensed partner, eligibility rules, fees, risks, and product terms must be shown before use.

The campus target and founding status do not override those requirements. Reaching 500 verified students is an early-access milestone, not approval for a financial account.

06

Report a safety concern

For a suspicious Brev message, a privacy request, or a campus-pass concern, email support@heybrev.com. Do not include passwords, full card or bank numbers, government IDs, verification links, or passkey secrets in the message.

If you believe financial or identity information was exposed outside Brev, contact the affected bank or provider directly and follow the reporting steps for your location.

plain answers

Frequently asked questions

Is Brev a bank?

No. Brev is a brand of Gus AI, Inc., a financial technology company, not a bank, broker-dealer, or investment adviser. Any regulated service would be provided through licensed partners under separate terms.

Does Brev hold my money during early access?

No. The current campus experience is a waitlist. Joining does not open an account, move money, or require a deposit.

Does Brev collect bank or card details for the waitlist?

No. The campus waitlist does not request bank account numbers, card numbers, a street address, a government ID, or a Social Security number.

Does Brev receive my fingerprint, face scan, or passkey private key?

No. The device or passkey provider handles the local unlock. Brev receives a signed response and stores public credential material used to verify it, not the private key or biometric data.

What should I do with a suspicious Brev email?

Do not use its links or attachments. Open heybrev.com yourself and email support@heybrev.com. Never send a verification link, password, bank login, card number, government ID, or passkey secret.

receipts, not rankings

Sources

  1. Brev early access terms ↗

    What joining the waitlist does and does not provide.

  2. Brev waitlist privacy notice ↗

    The data, security, retention, passkey, and deletion practices for campus early access.

  3. FIDO Alliance: passkeys ↗

    How domain-bound public-key passkeys work and why biometric data remains on the user’s device.

  4. FTC: recognize and avoid phishing ↗

    Official consumer guidance for checking unexpected messages and reporting phishing.

ready when your campus is.

Fund the plan.
Skip the chase.

join with your .edu ↗