# What Technologies Are Used in the Securo Backend API? A Complete Tech Stack Breakdown

> Discover the technologies powering the Securo backend API. Explore the tech stack including Python FastAPI SQLAlchemy Celery and Pydantic for robust development.

- Repository: [securo-finance/securo](https://github.com/securo-finance/securo)
- Tags: tech-stack-breakdown
- Published: 2026-08-28

---

**The Securo backend API is built on Python with FastAPI as the web framework, SQLAlchemy with AsyncPG for database operations, Celery with Redis for background tasks, and Pydantic for configuration management.**

Securo's backend is a production-ready, asynchronous Python service designed for financial data processing. According to the `securo-finance/securo` source code, the technology stack is explicitly declared in [`backend/pyproject.toml`](https://github.com/securo-finance/securo/blob/main/backend/pyproject.toml) and documented in the README's Tech Stack section. This article breaks down every layer of the architecture with direct references to the codebase.

## Web Framework and Server Layer

### FastAPI for API Endpoints

The core web framework is **FastAPI** (`>=0.109.0`), chosen for its automatic OpenAPI documentation generation and native type checking. In [`backend/app/main.py`](https://github.com/securo-finance/securo/blob/main/backend/app/main.py), the application is instantiated with configuration-driven settings:

```python

# File: backend/app/main.py

from fastapi import FastAPI, Depends
from app.api.accounts import router as accounts_router
from app.core.config import get_settings

settings = get_settings()

app = FastAPI(
    title=settings.app_name,
    openapi_url="/api/openapi.json",
    docs_url="/api/docs",
)

# Mount routers

app.include_router(accounts_router, prefix="/api/accounts")

```

This pattern demonstrates **modular router architecture** — each domain (accounts, transactions, assets) lives in its own FastAPI router under `app/api/` and is mounted centrally.

### Uvicorn ASGI Server

**Uvicorn** (`>=0.27.0`) serves as the ASGI server for production deployments. The combination of FastAPI + Uvicorn enables full async/await support across all endpoints.

## Database and ORM Technologies

### SQLAlchemy 2.0 with AsyncPG

The data layer uses **SQLAlchemy** (`>=2.0.0`) paired with **AsyncPG** (`>=0.29.0`) for asynchronous PostgreSQL operations. This async-first design ensures non-blocking database queries throughout the API.

### Alembic for Schema Migrations

**Alembic** (`>=1.13.0`) handles all database schema migrations, maintaining version control for structural changes.

## Configuration and Settings Management

### Pydantic Settings for Environment Variables

**Pydantic** (`>=2.5.0`) and **Pydantic-Settings** (`>=2.5.0`) provide strongly-typed configuration from environment variables. The [`backend/app/core/config.py`](https://github.com/securo-finance/securo/blob/main/backend/app/core/config.py) file defines the central `Settings` class:

```python

# File: backend/app/core/config.py

from pydantic_settings import BaseSettings

class Settings(BaseSettings):
    app_name: str = "Securo"
    frontend_url: str
    database_url: str
    redis_url: str
    # … many more env‑vars

    class Config:
        env_file = ".env"

```

This pattern enables **config-driven feature flags** — optional capabilities like AI agents or OIDC login are gated at import time based on environment variables.

## Authentication and Security Stack

Securo implements a multi-layered authentication system using four specialized libraries:

- **Python-Jose** (`>=3.3.0`) — JWT token handling
- **Cryptography** (`==46.0.7`) — Low-level cryptographic operations
- **Passlib** (`>=1.7.4`) — Password hashing
- **FastAPI-Users** (`>=13.0.0`) — Ready-made user management integration

The [`backend/app/core/auth.py`](https://github.com/securo-finance/securo/blob/main/backend/app/core/auth.py) file configures FastAPI-Users with JWT authentication. Protected endpoints use FastAPI's dependency injection:

```python

# File: backend/app/api/accounts.py

from fastapi import APIRouter, Depends
from app.core.auth import fastapi_users

router = APIRouter()

@router.get("/me")
async def read_current_user(user=Depends(fastapi_users.current_user())):
    return {"email": user.email, "id": user.id}

```

### Two-Factor and WebAuthn Support

Additional security layers include **pyotp** for TOTP-based 2FA and **webauthn** for passkey authentication.

## Background Processing Architecture

### Celery with Redis Broker

**Celery** (`>=5.3.0`) with **Redis** (`>=5.0.0`) powers the asynchronous task queue. The [`backend/app/worker.py`](https://github.com/securo-finance/securo/blob/main/backend/app/worker.py) file defines the Celery application, while `backend/app/tasks/` contains domain-specific task definitions.

```python

# File: backend/app/tasks/sync_tasks.py

from app.worker import celery_app

@celery_app.task(name="app.tasks.sync_tasks.sync_all_connections")
def sync_all_connections():
    # Logic that iterates over connections and triggers provider refreshes

    ...

```

Celery handles heavy operations including:
- Bank connection synchronization
- Foreign exchange rate updates
- Asset growth calculations
- AI agent data ingestion

## HTTP Client and External Integrations

### HTTPX for Async HTTP Requests

**httpx** (`>=0.26.0`) serves as the async HTTP client for external API calls, particularly to bank providers and financial data services.

## File Handling and Financial Data Processing

The backend includes specialized libraries for financial document processing:

| Library | Purpose |
|---------|---------|
| **python-multipart** | Form-data and file upload handling |
| **ofxparse** | OFX (Open Financial Exchange) file parsing |
| **yfinance** | Market data retrieval |
| **pgvector** | Vector search capabilities for embeddings |
| **pypdf** | PDF document parsing |
| **pyzipper** | Encrypted ZIP archive creation |

## AI and Embedding Technologies

### FastEmbed for Vector Embeddings

**fastembed** (`>=0.4.0`) provides optional knowledge-base embeddings for AI agents. When enabled via feature flag, this integrates with **pgvector** in PostgreSQL for semantic search capabilities.

## Key Architectural Patterns in Securo's Backend

Based on the source code analysis, three patterns define the Securo backend API architecture:

1. **Async-first design** — All endpoints and database interactions leverage `asyncio`, `httpx`, and SQLAlchemy's async engine. No synchronous I/O blocks the event loop.

2. **Dependency injection** — FastAPI's `Depends` system handles authentication, rate-limiting, and workspace resolution through `app/core/` modules.

3. **Modular domain separation** — Each business domain (accounts, transactions, assets) implements its own router, models, and tasks, mounted centrally in [`app/main.py`](https://github.com/securo-finance/securo/blob/main/app/main.py).

## Summary

- **Core framework**: FastAPI (`>=0.109.0`) with Uvicorn ASGI server
- **Database layer**: SQLAlchemy 2.0 + AsyncPG for async PostgreSQL operations, Alembic for migrations
- **Configuration**: Pydantic Settings for type-safe environment variable management
- **Authentication**: FastAPI-Users with JWT (Python-Jose), Passlib for hashing, plus pyotp and webauthn for 2FA/passkeys
- **Background jobs**: Celery (`>=5.3.0`) with Redis broker for async task processing
- **HTTP client**: httpx for external API integrations
- **Financial data**: Specialized libraries including ofxparse, yfinance, pypdf, and pgvector
- **Optional AI**: fastembed for knowledge-base embeddings when feature-enabled

## Frequently Asked Questions

### What Python version does Securo require?

The [`pyproject.toml`](https://github.com/securo-finance/securo/blob/main/pyproject.toml) specifies Python 3.11 or higher, leveraging modern `asyncio` features and type hint syntax that FastAPI and Pydantic v2 fully utilize.

### How does Securo handle database migrations?

Securo uses **Alembic** (`>=1.13.0`) for schema migrations. Migration scripts are maintained alongside the SQLAlchemy model definitions, with revision history tracked in the repository.

### Is Securo's backend fully asynchronous?

Yes. Every layer — from FastAPI endpoints through SQLAlchemy's async engine to httpx HTTP requests — uses `async`/`await` patterns. Even Celery tasks integrate with async code where beneficial, though Celery itself runs tasks in worker processes.

### What caching and task queue system does Securo use?

**Redis** serves double duty: as the Celery message broker for background task distribution and as a general-purpose cache layer for session storage and rate limiting.