Safety at Brev · 04
Safety at Brev
What exists today
Joining the Brev campus waitlist measures verified interest at a school. It does not open an account, move money, reserve a financial product, or require a deposit.
Public app screens show the direction of the product and are illustrative. Payment, yield, and investing features depend on licensed partners and may change or never launch.
- No bank account or card number is requested during campus early access
- No payment is required to join or keep a place on the waitlist
- A campus entry counts only after school-email verification and the private intake are complete
How campus access is protected
The sign-in flow limits how long emailed links and browser challenges can be used.
- 01
Verify a school email
The emailed verification link expires after 30 minutes. Opening the page does not consume it; explicitly continuing exchanges it once for a separate intake or campus-pass session.
- 02
Keep the campus pass private
Email and session tokens are stored as hashes. The signed-in campus pass uses an HttpOnly session cookie that page scripts cannot read and that expires after 30 days.
- 03
Add an optional passkey
A passkey challenge expires after 5 minutes. Brev stores the public credential needed to verify a signed response, not the private key or biometric used to unlock it.
- 04
Protect the recovery email
Email remains the recovery method. A passkey makes ordinary sign-in harder to phish, but keeping the school email secure still matters.
What the waitlist collects
Brev uses waitlist information to verify campus eligibility, prevent duplicate or automated signups, run campus invites, maintain the campus pass, and understand which pages work. The waitlist notice explains retention and deletion choices in detail.
| Stage | Information used | Boundary |
|---|---|---|
| School verification | School email, matched domain, request and completion times | No school password or mailbox access |
| Private intake | Full name, mobile number, date of birth, school confirmation, terms acceptance | No street address, government ID, Social Security number, bank details, or card number |
| Campus pass | Invite code, verified-friend count, session record, and optional public passkey credential | No passkey private key or biometric data |
| Site operation | Pages viewed, browser and device type, and approximate location derived from IP | Brev says it does not sell personal information or share it with advertisers for their own marketing |
How to recognize a suspicious message
- A current campus waitlist message should never require a deposit, wire transfer, cryptocurrency, or gift card to secure access
- Do not send a password, bank login, card number, government ID, passkey private key, or biometric data in response to a message
- Do not share a school-email verification link; it is intended only for the mailbox that requested it
- If a message feels unexpected, type heybrev.com into the browser yourself and contact support@heybrev.com instead of using the message’s links
- A lookalike sender name is not proof that a message came from Brev
Before money features can launch
Brev is a brand of Gus AI, Inc., a financial technology company, not a bank, broker-dealer, or investment adviser. If payment, cash-sweep, card, or investing features become available, the relevant licensed partner, eligibility rules, fees, risks, and product terms must be shown before use.
The campus target and founding status do not override those requirements. Reaching 500 verified students is an early-access milestone, not approval for a financial account.
Report a safety concern
For a suspicious Brev message, a privacy request, or a campus-pass concern, email support@heybrev.com. Do not include passwords, full card or bank numbers, government IDs, verification links, or passkey secrets in the message.
If you believe financial or identity information was exposed outside Brev, contact the affected bank or provider directly and follow the reporting steps for your location.
Frequently asked questions
Is Brev a bank?+
No. Brev is a brand of Gus AI, Inc., a financial technology company, not a bank, broker-dealer, or investment adviser. Any regulated service would be provided through licensed partners under separate terms.
Does Brev hold my money during early access?+
No. The current campus experience is a waitlist. Joining does not open an account, move money, or require a deposit.
Does Brev collect bank or card details for the waitlist?+
No. The campus waitlist does not request bank account numbers, card numbers, a street address, a government ID, or a Social Security number.
Does Brev receive my fingerprint, face scan, or passkey private key?+
No. The device or passkey provider handles the local unlock. Brev receives a signed response and stores public credential material used to verify it, not the private key or biometric data.
What should I do with a suspicious Brev email?+
Do not use its links or attachments. Open heybrev.com yourself and email support@heybrev.com. Never send a verification link, password, bank login, card number, government ID, or passkey secret.
Sources
- Brev early access terms ↗
What joining the waitlist does and does not provide.
- Brev waitlist privacy notice ↗
The data, security, retention, passkey, and deletion practices for campus early access.
- FIDO Alliance: passkeys ↗
How domain-bound public-key passkeys work and why biometric data remains on the user’s device.
- FTC: recognize and avoid phishing ↗
Official consumer guidance for checking unexpected messages and reporting phishing.
ready when your campus is.