
Features
Part of Digital account guide: banks, nonbanks, balances, insurance, and access
Mapping a fintech app's bank, ledger, and insurance disclosures case
Fintech account mapping case showing how to identify a nonbank, partner bank, pooled ledger, deposit placement, insurance conditions, support roles, and gaps.
What to take away
- Start with the agreement for the specific balance, not the app's general help center.
- A real insured partner bank does not prove that every displayed balance is an eligible deposit.
- Pooled deposits require a customer-level ownership and balance record somewhere in the chain.
- Insurance must be stated by institution failure, depositor, limit, and conditions.
- Unverified record access should change how much operational dependence the user accepts.
This fictional case uses invented companies, terms, balances, and correspondence. It shows how to map disclosures without declaring coverage that only the facts at a bank failure could establish.
The product
Riverlamp is a nonbank app offering three balances under one login:
- Spend:receives transfers and funds a debit card.
- Reserve:automatically moves part of each deposit into a labeled savings pocket.
- Invest:holds brokerage cash and exchange-traded fund shares.
The home screen shows $12,480 total. Owner Dana Brooks wants to know whether the full amount is FDIC-insured before using Riverlamp for business reserves.
First impression
The app footer says:
Banking services provided by Harbor Field Bank, Member FDIC. Eligible balances may be insured up to applicable limits.
That sentence supplies a bank name and a conditional claim. It does not identify which balances are deposits, when funds reach the bank, whether accounts are direct or pooled, or what happens to Invest cash.
Dana does not rewrite "may be" as "is."
Document collection
Dana downloads four agreements:
| Document | Applies to | Named entities |
|---|---|---|
| Riverlamp terms | App login and general service | Riverlamp Technologies LLC |
| Deposit program agreement | Spend and Reserve | Harbor Field Bank and Northline Program Services |
| Cardholder agreement | Debit card | Harbor Field Bank and card processor |
| Brokerage agreement | Invest | Trailrock Securities and listed sweep banks |
The privacy notice names another analytics vendor, but it does not hold money. Dana keeps it in the data map rather than the custody map.
Balance classification
The statements show:
The total is not one account.
Spend and Reserve
The deposit program agreement says Riverlamp accepts instructions, Northline maintains the end-user subledger, and customer funds are placed in a custodial account at Harbor Field Bank titled for the benefit of program users. Reserve is a label inside the same deposit program, not a second bank or ownership category.
Invest cash
The brokerage agreement says uninvested cash may remain at Trailrock briefly before moving to a sweep bank. Dana must check the current destination rather than assuming the bank named for Spend also holds it.
ETF shares
The shares are securities with market value. They are not deposits merely because the app adds them to a dollar total.
Verifying the pass-through structure
The FDIC describes pass-through deposit insurance as a method for insuring actual owners whose funds are placed at an insured bank through a third party. Its explanation says ownership, disclosure, and recordkeeping conditions matter and that pass-through is not a separate ownership category.
Dana extracts the represented facts:
| Condition to examine | Riverlamp evidence |
|---|---|
| Insured bank named | Harbor Field Bank |
| Custodial relationship disclosed | Yes, in deposit agreement |
| Actual owner identified | Agreement says program users |
| Customer balances recorded | Northline subledger described |
| Amount placed at bank | Not visible by user each day |
| Bank access to subledger | Not stated |
| Same-bank aggregation disclosed | Yes, general warning |
The missing rows do not prove ineligibility. They define what Dana cannot independently verify.
Checking the bank and account title
Dana confirms Harbor Field Bank in the official bank directory and matches the legal name, certificate number, and website. Riverlamp support confirms that Spend and Reserve share one pooled custodial deposit program.
Support will not say whether the bank receives daily user-level records. It says only that Riverlamp and Northline maintain records according to their agreements.
Dana writes the protection statement carefully:
Spend and Reserve are represented as beneficial interests in custodial deposits at Harbor Field Bank. They may qualify for pass-through FDIC insurance if applicable ownership, disclosure, recordkeeping, placement, limit, and other requirements are satisfied when the bank fails. The insurance does not cover Riverlamp's own failure.
That sentence is less convenient than "FDIC-insured up to $250,000," but it preserves the conditions.
Treating the labeled Reserve balance
The app displays Reserve as a separate tile with a higher interest rate. Dana initially assumes it receives separate insurance coverage.
The agreement contradicts that assumption. Spend and Reserve are subledger categories inside the same program at the same bank and held in the same ownership capacity. Moving $1,000 between them changes app labels, not necessarily the insured-bank ownership category.
Dana corrects the account map instead of searching for language that supports the original belief.
Mapping Invest
The brokerage statement shows $480 in "cash awaiting sweep" on month-end. The sweep disclosure lists three possible banks and says placement can change.
Dana records:
- brokerTrailrock Securities;
- pre-sweep positionbrokerage cash;
- post-sweep positiondeposit at the listed destination bank;
- securitiesETF shares, not deposits;
- app banknot necessarily the sweep bank;
- protectiondepends on where each asset is when the relevant institution fails.
She downloads the monthly destination report rather than relying on the home-screen total.
Comparing the app's disclosure with official consumer findings
The CFPB's analysis of funds stored through payment apps separates closed-loop app balances from funds moved to a bank or prepaid account. Stored funds may not sit in an insured account for every consumer.
Riverlamp's documents claim bank placement for Spend and Reserve, so Dana does not read the report as proof her balances lack coverage. She uses it to test the placement and recordkeeping claims.
This is the difference between source use and source decoration: the official report frames the risk; the product documents supply the product-specific representation.
Operational risk decision
Dana now separates protection from access:
| Risk | Evidence | Decision |
|---|---|---|
| Harbor Field Bank failure | Conditional pass-through representation | Stay below aggregated applicable limit |
| Riverlamp failure | Deposit insurance does not cover nonbank failure | Limit balance and keep alternate bank |
| Northline ledger outage | Bank access to user records unclear | Export monthly ledger and avoid payroll dependence |
| Brokerage failure | Separate broker framework | Keep Invest map and statements separately |
| App lockout | Riverlamp controls login | Maintain emergency funds outside app |
She decides Riverlamp can handle routine receipts but not the entire business reserve.
Questions sent to support
Dana asks:
- Does Harbor Field Bank receive customer-level beneficial-owner and balance data?
- How often are the subledger and pooled bank account reconciled?
- Can the bank provide user access if Riverlamp or Northline stops operating?
- When exactly do incoming funds become deposited at the bank?
- Which document identifies the current Invest sweep destination?
Support answers questions 2, 4, and 5 but not 1 or 3. Dana records partial verification rather than interpreting silence as confirmation.
Final account map
| Balance | Legal form represented | Primary institution | Customer ledger | Main unresolved point |
|---|---|---|---|---|
| Spend | Beneficial interest in custodial deposit | Harbor Field Bank | Northline | Bank access during nonbank failure |
| Reserve | Same deposit program, separate app label | Harbor Field Bank | Northline | Not a separate ownership category |
| Invest cash | Brokerage cash, then bank sweep | Trailrock, then destination bank | Trailrock | Location changes by sweep timing |
| ETF shares | Security | Trailrock custody | Trailrock | Market value and brokerage protection |
What the case establishes
The review establishes the represented structure, verifies the named bank and broker, identifies the ledger keeper, distinguishes balances, and records unknowns. It does not issue an insurance guarantee.
Dana's practical result is a limit on balance and dependence, plus a complete evidence file for future review.
Common questions
Why are Spend and Reserve not automatically insured separately?
App labels do not create separate banks or ownership categories. The underlying account title and insurance rules control.
Does verifying the bank prove placement?
No. It confirms the institution. Product records must support when and how funds are placed there.
Can a source about payment apps decide one product's coverage?
No. It can identify general risks and questions. Product-specific agreements and actual records determine the represented arrangement.
What changed Dana's behavior?
The unresolved dependency on the nonbank subledger and access path led her to limit funds and keep an independent bank account.







