Sorry but thatâs completely wrong.
You never give TrueLayer your online banking password or actual access details (with which they could be able to login on your behalf).
What happens when you try to setup an instant transfer via the T212 app is (simplified):
1- T212 takes you to the TrueLayer website
2- On the TrueLayer website you select the bank of the account you want to link, amongst the âcompatibleâ banks
3- You get taken to the bankâs own website or mobile app, where youâll login to your account via the online banking/app bank ownâs infrastructure
4- On the bankâs online banking website or app, you grant access to TrueLayer by giving them a âtokenâ (which you can revoke anytime via your bankâs online banking interface or mobile app), not by sharing to them your login credentials
5- Then you get redirected back to TrueLayer
6- TrueLayer thanks to this token gets access to read-only details about whatâs in your account (i.e. they donât get details about how you login to your account) and will be able to act as speedy middleman between T212 and your bank
And now, your bank account is linked, via TrueLayer, to T212.
Then, whenever you need to make an instant transfer, what happens is that T212 will seamlessly take you to your own bankâs online banking or app via TrueLayer (which means you wonât have to deal with TrueLayer again, theyâll literally just be a half-a-second redirect between T212 and your bank ownâs login page).
The âvia TrueLayerâ part (that again, once youâve set-up your account for the first time then becomes completely transparent to you) is what allows T212 to have the exact deposit amount (that you previously chose within the T212 interface) and T212 âreceiving accountâ details showing up, pre-filled, in your bankâs own online banking site or mobile app (to which youâll get access via logging in to your bankâs app or online banking as normal, not on TrueLayer domain). So then (after finding yourself in your online banking/app) you can just authorise the transaction (again: YOU need to authorise it, or it wonât go through) using your usual means of authentication that your bank has set-up on their own website/app.
Hope this makes it a bit clearer, and sorry for the broken English
I will add, but thatâs just a personal consideration, that the fact your IT security professional of reference doesnât know what TrueLayer is how how it works, is a bit concerning.