{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "powens",
    "name": "Powens",
    "vendor": "Powens SAS",
    "vendorUrl": "https://www.powens.com",
    "kind": "http-api",
    "category": "banking-data",
    "summary": "Powens is a French open banking platform, formerly Budget Insight. Its REST API and hosted Webview read bank accounts, balances and transactions with the account holder's consent, verify account ownership and start bank payments in Europe.",
    "url": "https://www.anchorterminal.com/tools/powens",
    "markdownUrl": "https://www.anchorterminal.com/tools/powens.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/powens.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/powens.json",
    "repo": "https://github.com/powenscompany/powens-connect-ios",
    "license": "Proprietary service under Powens' General Terms and Conditions of Sale. The Powens Connect iOS SDK on GitHub is LGPL-3.0",
    "transports": [
      "http"
    ],
    "remoteUrl": "https://{domain}.biapi.pro/2.0",
    "packages": [],
    "auth": "mixed",
    "authNotes": "A client ID and client secret from the console, sent in the body of `POST /auth/init`, return a permanent user token that is sent as `authorization: Bearer`. A permanent token has no expiry and is revoked with `DELETE /auth/token` or `POST /auth/renew` with `revoke_previous`. The Webview takes a temporary code from `GET /auth/token/code`, valid 30 minutes or once. Payments use 30-minute service tokens with `payments:*` scopes. Listing users and changing configuration need separate tokens from the console settings. Console signup is self-serve for a sandbox domain. Live access is by purchase order.",
    "pricing": "paid",
    "pricingNotes": "No public prices. The site has no pricing page, and product pages lead to a meeting request (https://www.powens.com/products/transactions/, checked 2026-10-09). The conditions of sale set fees in a purchase order by volume of users, invoiced in advance with a monthly invoice for excess users, and revise prices each year by the SYNTEC index. A free console account gives a sandbox domain with a test connector. No card is mentioned for signup.",
    "priceSummary": "Paid",
    "where": "hosted",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the docs index, the API reference pages read or the site (checked 2026-10-09).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": null,
      "pypiWeekly": null,
      "asOf": "2026-10-09"
    },
    "docsUrl": "https://docs.powens.com/documentation",
    "llmsTxt": "https://docs.powens.com/api-reference/llms.txt",
    "capabilities": [
      "bank.accounts",
      "bank.transactions",
      "bank.consent",
      "bank.identity",
      "bank.payments"
    ],
    "tags": [
      "hosted",
      "llms-txt",
      "webhooks",
      "sandbox",
      "eu",
      "enterprise",
      "sales-led",
      "closed-source"
    ],
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 42.6,
      "grade": "E",
      "agentReady": false,
      "rank": 892,
      "ranked": true,
      "rankOf": 950,
      "categoryRank": 13,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 57,
        "maintenance": 33,
        "payments": 10,
        "reliability": 27,
        "schema": 48,
        "security": 60,
        "transparency": 63
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 27,
          "points": 5.4,
          "reason": "Graded with the hosted lines. No status page is linked from the home page, the product pages or the docs read. status.powens.com was a guess that our network could not reach, so this is scored absent and listed as unchecked (0 of 20). No readable incident history (5 of 30). The fair usage policy publishes sandbox limits of 30 calls a minute and 86,400 a day. Production limits are not published (10 of 15). The policy says rate limiting exists and asks for webhooks before polling. No 429 status, Retry-After, backoff guidance or idempotency key was found, and the response code table has no 429 (2 of 15). The conditions of sale carry no uptime figure. The site states 99.9 per cent historical API availability and a committed 95 per cent connection success rate as claims, not as a published SLA (0). Version 2.0 is the current API with no beta label (10)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 48,
          "points": 7.8,
          "reason": "No OpenAPI file or other machine-readable contract was found. The reference is hand-written GitBook tables (0 of 25). Both docs spaces publish llms.txt and a Markdown twin of every page (10). Each resource page opens with what the resource is, and endpoints say which token they need and how soft-deleted items behave. Several endpoints have no description beyond the title (12 of 20). Parameters and objects are in tables with types, required marks and value lists for states and scopes. Configuration and client `config` are free key-value objects (9 of 15). Guides carry curl requests and JSON responses. The reference pages read have few examples, and the errors page lists five common codes and warns that others may appear (9 of 15). The version is in the path (2.0). The changelog is a Notion page that is drawn by script and was not read (8 of 15)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 57,
          "points": 9.26,
          "reason": "Lists take `limit` up to 1,000 and `expand` pulls linked resources into one response. No field selection was found (17 of 25). `limit` and `offset` on most lists, opaque cursor links in `_links` on transactions, and `min_date`, `max_date`, `last_update`, value and wording filters (18 of 20). One error format with `code`, `description`, an optional bank message and `request_id`, and advice to branch on the code. The documented code list is short (13 of 20). No idempotency key was found, including on `POST /payments`. Reads are safe to repeat (4 of 20). A first data call needs a console domain, a client application, a user token, a temporary code and a browser consent. `limit` is required on transactions. The only SDK found is an iOS beta from 2024 (5 of 15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 60,
          "points": 10.5,
          "reason": "A client ID and secret from the console, sent in the request body, issue permanent user tokens that never expire and are revoked with `DELETE /auth/token` or `POST /auth/renew`. The secret can be reset with `PUT /clients/{clientAppId}`. Payment service tokens last 30 minutes and carry scopes. A user token has no read-only form. The Webview takes a 30-minute or single-use code in the URL in place of the token, so no deduction was taken (22 of 30). Payments have separate read-only, validate and cancel scopes, accounts stay disabled until the account holder consents, and `payment.max_amount` caps payment size. A user token can delete its user and connections (13 of 20). Responses carry bank-written transaction wording and bank error messages, and no guidance on treating them as untrusted was found (6 of 15). `GET /config/logs` lists configuration changes, connections have a logs endpoint, and errors carry a `request_id` (9 of 15). The site says Powens is ISO 27001 certified and that security is tested and audited each year, with no certificate published. security.txt returns 404, and no disclosure policy or bug bounty was found (10 of 20)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 10,
          "points": 1.25,
          "reason": "No x402, MPP or L402 (0). No public prices. Fees are set in a purchase order by volume of users (0). A free, self-serve console account with a sandbox domain and a test connector, no card mentioned. No free live tier (10 of 20). A person signs up in the console (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 33,
          "points": 2.89,
          "reason": "The public changelog is a Notion page drawn by script and was not read, so recency is taken from the docs sitemap. The newest reference page change is dated 15 September 2026, 24 days before the check, scored 20 of 30 because docs metadata is weaker evidence than a release note. Docs pages changed on two dates in the last 90 days, 31 August and 15 September, and dated changelog entries could not be counted (0 of 20). Closed service with a linked changelog, a support desk on Jira and support hours of 9.30am to 7pm on working days in the conditions of sale (8 of 15). The iOS SDK is at 1.0.0-beta with its last commit on 1 October 2024, Android is marked coming soon, and no server-side SDK was found (3 of 15). The SDK repository holds a binary framework with no CI workflow (2 of 10)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 63,
          "points": 5.51,
          "note": "editorial 64, provenance 61",
          "reason": "Closed service with public General Terms and Conditions of Sale under French law. The page has no version or date. The iOS SDK is LGPL-3.0 (15 of 30). The conditions of sale include a data protection annex, say collected data is destroyed at most 30 days after the contract ends, and the privacy policy gives retention periods by purpose. Neither page is dated, and the end-user terms say no data leaves the EU while the privacy policy lists business tools with transfers outside it (22 of 30). Obsolete and deprecated items are marked in the docs with no dates, and the conditions of sale say backward compatibility is assured but may be limited, with no notice period (5 of 20). The conditions of sale name Sewan and AWS, OVH and Gemalto in France and Unnax and CRIF in Spain and Italy, and commit to servers in the EU (17 of 20). Regulatory standing counts here as an addition to the checklist, as for the other bank data listings. Powens SAS is a payment institution registered with the ACPR under CIB 16948 (+5)."
        }
      ],
      "assessment": {
        "date": "2026-10-09",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "Lists take `limit` up to 1,000 and `expand` pulls linked resources into one response. No field selection was found (17 of 25). `limit` and `offset` on most lists, opaque cursor links in `_links` on transactions, and `min_date`, `max_date`, `last_update`, value and wording filters (18 of 20). One error format with `code`, `description`, an optional bank message and `request_id`, and advice to branch on the code. The documented code list is short (13 of 20). No idempotency key was found, including on `POST /payments`. Reads are safe to repeat (4 of 20). A first data call needs a console domain, a client application, a user token, a temporary code and a browser consent. `limit` is required on transactions. The only SDK found is an iOS beta from 2024 (5 of 15).",
          "maintenance": "The public changelog is a Notion page drawn by script and was not read, so recency is taken from the docs sitemap. The newest reference page change is dated 15 September 2026, 24 days before the check, scored 20 of 30 because docs metadata is weaker evidence than a release note. Docs pages changed on two dates in the last 90 days, 31 August and 15 September, and dated changelog entries could not be counted (0 of 20). Closed service with a linked changelog, a support desk on Jira and support hours of 9.30am to 7pm on working days in the conditions of sale (8 of 15). The iOS SDK is at 1.0.0-beta with its last commit on 1 October 2024, Android is marked coming soon, and no server-side SDK was found (3 of 15). The SDK repository holds a binary framework with no CI workflow (2 of 10).",
          "payments": "No x402, MPP or L402 (0). No public prices. Fees are set in a purchase order by volume of users (0). A free, self-serve console account with a sandbox domain and a test connector, no card mentioned. No free live tier (10 of 20). A person signs up in the console (0).",
          "reliability": "Graded with the hosted lines. No status page is linked from the home page, the product pages or the docs read. status.powens.com was a guess that our network could not reach, so this is scored absent and listed as unchecked (0 of 20). No readable incident history (5 of 30). The fair usage policy publishes sandbox limits of 30 calls a minute and 86,400 a day. Production limits are not published (10 of 15). The policy says rate limiting exists and asks for webhooks before polling. No 429 status, Retry-After, backoff guidance or idempotency key was found, and the response code table has no 429 (2 of 15). The conditions of sale carry no uptime figure. The site states 99.9 per cent historical API availability and a committed 95 per cent connection success rate as claims, not as a published SLA (0). Version 2.0 is the current API with no beta label (10).",
          "schema": "No OpenAPI file or other machine-readable contract was found. The reference is hand-written GitBook tables (0 of 25). Both docs spaces publish llms.txt and a Markdown twin of every page (10). Each resource page opens with what the resource is, and endpoints say which token they need and how soft-deleted items behave. Several endpoints have no description beyond the title (12 of 20). Parameters and objects are in tables with types, required marks and value lists for states and scopes. Configuration and client `config` are free key-value objects (9 of 15). Guides carry curl requests and JSON responses. The reference pages read have few examples, and the errors page lists five common codes and warns that others may appear (9 of 15). The version is in the path (2.0). The changelog is a Notion page that is drawn by script and was not read (8 of 15).",
          "security": "A client ID and secret from the console, sent in the request body, issue permanent user tokens that never expire and are revoked with `DELETE /auth/token` or `POST /auth/renew`. The secret can be reset with `PUT /clients/{clientAppId}`. Payment service tokens last 30 minutes and carry scopes. A user token has no read-only form. The Webview takes a 30-minute or single-use code in the URL in place of the token, so no deduction was taken (22 of 30). Payments have separate read-only, validate and cancel scopes, accounts stay disabled until the account holder consents, and `payment.max_amount` caps payment size. A user token can delete its user and connections (13 of 20). Responses carry bank-written transaction wording and bank error messages, and no guidance on treating them as untrusted was found (6 of 15). `GET /config/logs` lists configuration changes, connections have a logs endpoint, and errors carry a `request_id` (9 of 15). The site says Powens is ISO 27001 certified and that security is tested and audited each year, with no certificate published. security.txt returns 404, and no disclosure policy or bug bounty was found (10 of 20).",
          "transparency": "Closed service with public General Terms and Conditions of Sale under French law. The page has no version or date. The iOS SDK is LGPL-3.0 (15 of 30). The conditions of sale include a data protection annex, say collected data is destroyed at most 30 days after the contract ends, and the privacy policy gives retention periods by purpose. Neither page is dated, and the end-user terms say no data leaves the EU while the privacy policy lists business tools with transfers outside it (22 of 30). Obsolete and deprecated items are marked in the docs with no dates, and the conditions of sale say backward compatibility is assured but may be limited, with no notice period (5 of 20). The conditions of sale name Sewan and AWS, OVH and Gemalto in France and Unnax and CRIF in Spain and Italy, and commit to servers in the EU (17 of 20). Regulatory standing counts here as an addition to the checklist, as for the other bank data listings. Powens SAS is a payment institution registered with the ACPR under CIB 16948 (+5)."
        },
        "sources": [
          {
            "what": "docs index for agents (integration guides)",
            "url": "https://docs.powens.com/documentation/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "API reference index for agents",
            "url": "https://docs.powens.com/api-reference/llms.txt",
            "seen": "2026-10-09"
          },
          {
            "what": "API design, versioning, response codes and pagination",
            "url": "https://docs.powens.com/api-reference/overview/api-design.md",
            "seen": "2026-10-09"
          },
          {
            "what": "authentication, token types and scopes",
            "url": "https://docs.powens.com/api-reference/overview/authentication.md",
            "seen": "2026-10-09"
          },
          {
            "what": "error format and codes",
            "url": "https://docs.powens.com/api-reference/overview/errors.md",
            "seen": "2026-10-09"
          },
          {
            "what": "fair usage policy and sandbox rate limits",
            "url": "https://docs.powens.com/api-reference/overview/fair-usage-policy.md",
            "seen": "2026-10-09"
          },
          {
            "what": "connections reference, including deletion",
            "url": "https://docs.powens.com/api-reference/user-connections/connections.md",
            "seen": "2026-10-09"
          },
          {
            "what": "bank transactions reference",
            "url": "https://docs.powens.com/api-reference/products/data-aggregation/bank-transactions.md",
            "seen": "2026-10-09"
          },
          {
            "what": "configuration keys and configuration logs",
            "url": "https://docs.powens.com/api-reference/api-setup/configuration.md",
            "seen": "2026-10-09"
          },
          {
            "what": "quick start, console signup and sandbox",
            "url": "https://docs.powens.com/documentation/integration-guides/quick-start.md",
            "seen": "2026-10-09"
          },
          {
            "what": "webhooks and their authentication",
            "url": "https://docs.powens.com/documentation/integration-guides/webhooks.md",
            "seen": "2026-10-09"
          },
          {
            "what": "API reference sitemap with page modification dates",
            "url": "https://docs.powens.com/api-reference/sitemap-pages.xml",
            "seen": "2026-10-09"
          },
          {
            "what": "General Terms and Conditions of Sale",
            "url": "https://www.powens.com/sas-conditions-sale/",
            "seen": "2026-10-09"
          },
          {
            "what": "privacy policy",
            "url": "https://www.powens.com/sas-privacy-policy/",
            "seen": "2026-10-09"
          },
          {
            "what": "legal notice with company and ACPR registration",
            "url": "https://www.powens.com/sas-legal-notice/",
            "seen": "2026-10-09"
          },
          {
            "what": "platform page with certification and availability claims",
            "url": "https://www.powens.com/platform/",
            "seen": "2026-10-09"
          },
          {
            "what": "Transactions product page, no prices",
            "url": "https://www.powens.com/products/transactions/",
            "seen": "2026-10-09"
          },
          {
            "what": "coverage by country",
            "url": "https://www.powens.com/coverage/",
            "seen": "2026-10-09"
          },
          {
            "what": "iOS SDK repository (shallow clone, tags and log)",
            "url": "https://github.com/powenscompany/powens-connect-ios",
            "seen": "2026-10-09"
          },
          {
            "what": "domain registration",
            "url": "https://rdap.verisign.com/com/v1/domain/powens.com",
            "seen": "2026-10-09"
          }
        ],
        "openQuestions": [
          "unchecked: the public changelog on Notion, which is drawn by script. The last release date and the count of dated entries in 90 days were not established, and `lastRelease` is left empty",
          "unchecked: whether a status page exists. None is linked from the pages read, and status.powens.com could not be reached from our network",
          "unchecked: 27 of the 40 API reference pages, including balances, identities, investments and payment links. The operation count covers the nine resource pages read",
          "unchecked: the console itself (signup steps, whether a card is asked for, audit logs, production rate limits), which sits behind a login",
          "unchecked: GitHub stars and issue replies on the iOS SDK repository. The GitHub API was not queried",
          "The conditions of sale and the privacy policy carry no version or effective date",
          "The ISO 27001 claim on powens.com has no certificate, scope or issuing body published on the pages read",
          "Coverage is stated as 11 countries on one page, 12 on another and 12+ in the FAQ, and the coverage page lists 11 for Transactions",
          "Payments, virtual IBANs and transfers, partly from the former Unnax platform with its own developer site, were not graded. This listing covers the bank data API at biapi.pro"
        ]
      },
      "negative": 0,
      "verdict": "Powens documents a REST API with Markdown docs, cursor pagination, date filters and a hard-delete call for connections, under a French payment institution licence. No OpenAPI file, public price, status page, idempotency key or server SDK was found, and live access needs a signed purchase order.",
      "bestFor": "A European product, strongest in France, that needs account and transaction data plus wealth, loan and document data under Powens' own licence.",
      "strengths": [
        "Both docs spaces publish llms.txt and a Markdown twin of every page, and robots.txt states `ai-input=yes`",
        "Transactions take `limit` up to 1,000, opaque cursor links, `min_date`, `max_date`, `last_update` and value filters",
        "`DELETE /users/{userId}/connections/{connectionId}` is documented as a permanent erasure of the connection and all its data",
        "Payment service tokens last 30 minutes and carry scopes such as `payments:read-only`, `payments:validate` and `payments:cancel`",
        "Powens SAS is a payment institution registered with the ACPR under CIB 16948, and its terms name hosting sub-processors in France"
      ],
      "weaknesses": [
        "No OpenAPI or other machine-readable contract was found. The reference is hand-written tables",
        "No public prices. Fees are set per volume of users in a signed purchase order",
        "No status page is linked from the site or docs read, and no uptime SLA appears in the conditions of sale",
        "No idempotency key or documented 429 handling was found, and production rate limits are not published",
        "The only SDK found is an iOS package at 1.0.0-beta, last changed on 1 October 2024"
      ],
      "agentNotes": [
        "Ask the owner for the domain name, client ID and client secret from the console. Every call goes to `https://{domain}.biapi.pro/2.0`",
        "Send `limit` on every transactions list. It is required, at most 1,000, and the next page comes from `_links.next.href` used as given",
        "Enable an account with `POST` and `{\"disabled\": false}` only after the account holder consents. Accounts arrive disabled with no transactions",
        "Store the permanent user token as a secret. It does not expire, and the default webhook sends it in the `Authorization` header",
        "Stay under 30 calls a minute in the sandbox and use webhooks in place of polling, as the fair usage policy asks"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "E",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 42.6
        }
      ],
      "editorialScores": {
        "ergonomics": 57,
        "maintenance": 33,
        "payments": 10,
        "reliability": 27,
        "schema": 48,
        "security": 60,
        "transparency": 64
      },
      "provenanceScore": 61
    },
    "connect": {
      "http": "curl https://{domain}.biapi.pro/2.0/connectors/"
    },
    "letme": {
      "capability": "https://letme.dev/bank.accounts",
      "tool": "https://letme.dev/powens"
    },
    "notable": [
      "The API reference is a second GitBook space with its own llms.txt, and every page has a Markdown twin at the same address with `.md` (https://docs.powens.com/api-reference/llms.txt)",
      "Deleting a connection is described as a hard delete that erases accounts, transactions and history from Powens' databases (https://docs.powens.com/api-reference/user-connections/connections)",
      "The fair usage policy publishes sandbox limits of 30 calls a minute and 86,400 a day and asks customers to use webhooks before polling (https://docs.powens.com/api-reference/overview/fair-usage-policy)",
      "Bank accounts are created disabled, with only a name and no transactions, until the account holder consents (https://docs.powens.com/documentation/integration-guides/transactions/transactions-integration-guide)",
      "The conditions of sale say all servers are in the European Union and that collected data is destroyed at most 30 days after the contract ends (https://www.powens.com/sas-conditions-sale/)",
      "Every docs page ends with a GitBook block headed Agent Instructions that tells AI agents to query the docs with an `ask` parameter. We recorded it and did not act on it (https://docs.powens.com/documentation/llms.txt)",
      "Two endpoint addresses in the reference are misprinted, `{domain}.biapi/pro/2.0` on the account update and `{domain}.biapi/pro.2.0` on the certificate call (https://docs.powens.com/api-reference/api-setup/configuration)"
    ],
    "area": "domain-data",
    "details": [
      {
        "label": "API",
        "value": "REST, version 2.0, at https://{domain}.biapi.pro/2.0, one subdomain per customer domain. JSON or form-encoded requests, JSON responses. 50 operations on the nine resource pages read"
      },
      {
        "label": "Data endpoints",
        "value": "`GET /users/{userId}/accounts`, `GET /users/{userId}/transactions`, balances, account ownerships, investments, loans and documents. `me` stands for the token's user"
      },
      {
        "label": "Consent",
        "value": "The account holder picks a bank and consents in the Webview at webview.powens.com. Accounts are disabled until consent. PSD2 consent is renewed every 180 days, signalled by the `SCARequired` and `webauthRequired` states"
      },
      {
        "label": "Revocation",
        "value": "`DELETE /users/{userId}/connections/{connectionId}` erases the connection and its data permanently. `DELETE /users/{userId}` deletes a user and `DELETE /auth/token` revokes a permanent token"
      },
      {
        "label": "Tokens",
        "value": "Permanent user tokens from `POST /auth/init` with the client ID and secret, 30-minute temporary codes for the Webview, 30-minute service tokens with `payments:*` scopes, and console tokens for users and configuration"
      },
      {
        "label": "Pagination",
        "value": "`limit` (at most 1,000) and `offset`, cursor links in `_links` on some lists, `min_date`, `max_date` and `expand` for linked resources"
      },
      {
        "label": "Rate limits",
        "value": "Sandbox 30 calls a minute and 86,400 a day. Production limits are not published and are agreed with an account manager"
      },
      {
        "label": "Errors",
        "value": "One JSON format with `code`, `description`, `message` and `request_id`. Common codes are `missingParameter`, `invalidValue`, `methodNotAllowed`, `connectionLocked` and `bug`"
      },
      {
        "label": "Sandbox",
        "value": "Free console account, domain suffixed `-sandbox.biapi.pro`, and a test connector that accepts any username with the password 1234"
      },
      {
        "label": "Coverage",
        "value": "Powens says 1,800+ banks. Transactions in 11 countries per the coverage page (France, Portugal, Belgium, Austria, Spain, Germany, Luxembourg, Czech Republic, Italy, Netherlands, Ireland)"
      },
      {
        "label": "Webhooks",
        "value": "Registered in the console. Retried until a 2XX. Secured by the user token in the `Authorization` header by default, or an HMAC-SHA256 `BI-Signature` header"
      },
      {
        "label": "Sub-processors",
        "value": "Sewan and AWS for production hosting, OVH for backups, Gemalto (Thales) for encryption, all in France, and Unnax and CRIF for categorisation in Spain and Italy, per the conditions of sale"
      },
      {
        "label": "Certifications",
        "value": "ISO 27001 certified per powens.com/platform, which also says security is independently tested and audited each year. No certificate or report is published"
      },
      {
        "label": "SDKs",
        "value": "Powens Connect iOS 1.0.0-beta (LGPL-3.0, last commit 1 October 2024). Android is marked coming soon. No server-side SDK found"
      }
    ],
    "provenance": {
      "legalEntity": "Powens SAS",
      "domain": "powens.com",
      "domainRegistered": "2000-03-01",
      "endpointOnVendorDomain": false,
      "terms": "https://www.powens.com/sas-conditions-sale/",
      "privacy": "https://www.powens.com/sas-privacy-policy/",
      "statusPage": "",
      "changelog": "https://budget-insight.notion.site/Changelog-public-edc79d1d9e0a4608928df68fafa811bb",
      "securityTxt": "none",
      "checked": "2026-10-09",
      "notes": [
        "The legal notice names Powens, a simplified joint-stock company with share capital of 44,037.90 euros, 84 rue Beaubourg, 75003 Paris, Paris trade register number 749 867 206, registered with the ACPR as a payment institution under CIB 16948.",
        "The terms link is the General Terms and Conditions of Sale, which apply to services Powens performs for clients under a purchase order and are governed by French law. The page carries no version or date. A separate Terms and Conditions of Use page binds the account holders who use the Webview.",
        "The privacy link is the Powens SAS privacy policy, which covers the website, console accounts and financial data, and lists processors with a column for transfers outside the EU. The page carries no date. A group privacy policy and one for the Spanish regulated entity are separate pages.",
        "The API answers at https://{domain}.biapi.pro, a second domain registered on 5 February 2014, and the Webview at webview.powens.com. The docs still link console.budget-insight.com and docs.budget-insight.com in places.",
        "www.powens.com/.well-known/security.txt returns 404. No vulnerability disclosure policy or bug bounty was found on the pages read.",
        "No status page is linked from the home page, the product pages or the docs read. status.powens.com was a guess and could not be reached from our network, so its existence is unchecked.",
        "The changelog is a Notion page linked from the docs home. It is drawn by script and was not read. Verisign RDAP gives the powens.com registration date and OVH as registrar.",
        "Powens acquired the Spanish electronic money institution Unnax in 2024, and Unnax took the Powens brand in 2026 per powens.com/unnax-is-powens."
      ],
      "score": 61,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Powens SAS",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "powens.com, registered 2000-03-01 (26 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": "{domain}.biapi.pro is not on powens.com",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Terms of service",
          "value": "read, states 4 of the 7 things a reader expects",
          "points": 7.4,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 6 of the 8 things a reader expects",
          "points": 8.5,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Status page",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "Changelog",
          "value": "published",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://www.powens.com/sas-conditions-sale/",
          "state": "read",
          "readAt": "2026-10-09",
          "words": 9599,
          "points": 7.4,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "In the event of failure to reach an amicable agreement, the dispute shall fall under the exclusive jurisdiction of the Commercial Court of Paris or the International Chamber of the Paris Court of Appeal in case that the Client’s headquarter is based out of France.",
              "says": "Disputes go to the courts of Paris"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "In any event, the total liability of the Service Provider shall not exceed the total amount actually received by the Service Provider for the right of use in the calendar year in which the incident occurs."
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "The Contract shall then be renewed by tacit agreement for successive periods as indicated in the Purchase Order, unless terminated by either Party by physical or electronic registered mail with acknowledgement of receipt, at least ninety (90) days before the expiration of the current period."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "In the event of such a change, the Service Provider shall amend this Agreement and/or notify the Client within a reasonable period of time in order to implement the appropriate adjustments.",
              "says": "Says it gives notice of a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": false
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The contract renews tacitly for successive periods unless either party terminates by registered mail at least 90 days before the current period ends.",
              "quote": "The Contract shall then be renewed by tacit agreement for successive periods as indicated in the Purchase Order, unless terminated by either Party by physical or electronic registered mail with acknowledgement of receipt, at least ninety (90) days before the expiration of the current period."
            },
            {
              "date": "2026-10-08",
              "text": "Powens reserves the right to create anonymous datasets from collected data and transfer them to business partners.",
              "quote": "Creating anonymous datasets from historical and future collected data that can be transferred to business partners.*"
            },
            {
              "date": "2026-10-08",
              "text": "The client authorises Powens to use its trade name and logo for marketing during the whole contract period.",
              "quote": "The Client authorizes the use of its trade name and logo by the Service Provider for marketing purposes and in its commercial documents intended for the public during the entire contractual period."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://www.powens.com/sas-privacy-policy/",
          "state": "read",
          "readAt": "2026-10-09",
          "words": 2002,
          "points": 8.5,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": false
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "We may collect different types of personal data concerning you, including:"
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "In the context of a job application, your CV/resume and the information provided during the recruitment process will be retained for up to two (2) years after your last contact with Powens, unless you object.",
              "says": "Names a period of two years"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "is an entity registered in Spain with tax identification number B66353913 that operates as a reseller of third-party services and a provider of data solutions in Mexico."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": false
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "Right to rectification of personal data that is inaccurate, outdated, or incomplete."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "For any questions regarding the processing of your personal data, please feel free to contact us via email at dpo(@)powens.com.",
              "says": "Names a data protection officer"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Where necessary, we execute the Standard Contractual Clauses (SCCs) and ensure that appropriate supplementary measures have been implemented.",
              "says": "Relies on standard contractual clauses"
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/powens.json",
    "live": {
      "slug": "powens",
      "probe": {
        "target": "https://{domain}.biapi.pro/2.0",
        "method": "get",
        "lastAt": "2026-10-10T02:07:21.120408298Z",
        "lastOk": false,
        "lastStatus": 0,
        "lastMs": 0,
        "lastNote": "invalid character \"{\" in host name",
        "authRequired": false,
        "uptime24h": 0,
        "uptime30d": 0,
        "p50ms24h": 0,
        "p95ms24h": 0,
        "samples24h": 107,
        "samples30d": 107,
        "days": [
          {
            "date": "2026-10-09",
            "probes": 85,
            "ok": 0
          },
          {
            "date": "2026-10-10",
            "probes": 22,
            "ok": 0
          }
        ],
        "outages": [
          {
            "start": "2026-10-09T15:43:17.921158871Z",
            "end": "0001-01-01T00:00:00Z",
            "note": "invalid character \"{\" in host name"
          }
        ]
      },
      "versions": [
        {
          "registry": "github",
          "name": "powenscompany/powens-connect-ios",
          "version": "1.0.0-beta",
          "released": "2024-09-30",
          "seenAt": "2026-10-09T17:14:20.632650104Z"
        }
      ],
      "githubStars": 1,
      "pages": [
        {
          "url": "https://budget-insight.notion.site/Changelog-public-edc79d1d9e0a4608928df68fafa811bb",
          "kind": "changelog",
          "status": 404,
          "checkedAt": "2026-10-09T18:33:19.38191606Z",
          "changedAt": "0001-01-01T00:00:00Z"
        },
        {
          "url": "https://www.powens.com/sas-privacy-policy/",
          "kind": "privacy",
          "status": 200,
          "checkedAt": "2026-10-09T18:53:14.750162665Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "4bbb4f60d121"
        },
        {
          "url": "https://www.powens.com/sas-conditions-sale/",
          "kind": "terms",
          "status": 200,
          "checkedAt": "2026-10-09T18:53:12.685497091Z",
          "changedAt": "0001-01-01T00:00:00Z",
          "fingerprint": "7ce097c66886"
        }
      ],
      "updatedAt": "2026-10-10T02:07:21.120408298Z"
    }
  }
}
