Why the split matters, in one sentence. Deposit insurance covers the failure of an insured bank. Where the app is itself the insured bank, that is the end of the analysis. Where the app is a technology company placing customer money at a partner bank, the coverage still attaches to the bank, and the question becomes whether the records establish whose money is whose. The fintech page teaches that mechanism in full and it is not repeated here; the FDIC insurance page carries the limit and the ownership categories.
The rule that binds a non-bank making claims about FDIC coverage. 12 CFR part 328 subpart B is not addressed to banks. Its scope provision, 12 CFR 328.100, applies to "any person" who falsely represents that a deposit is FDIC-insured, knowingly misrepresents that it is insured or the extent or manner of insurance, or aids and abets someone doing so. "Person" is defined to include any corporation or other entity.
The operative prohibition, 12 CFR 328.102, then does three things a consumer can check on an app's own screens.
It bars a firm from using FDIC-associated terms in its business name to imply that an uninsured product is insured.
It treats a statement as materially incomplete where a person other than an insured bank represents that a product is FDIC-insured and "fails to clearly and conspicuously identify the insured depository institution(s) with which the representing party has a direct or indirect business relationship for the placement of deposits and into which the consumer's deposits may be placed." That is the origin of the "Banking services provided by [Bank], Member FDIC" line at the bottom of these apps: it is not branding, it is the identification the rule requires.
And it treats as materially incomplete a statement that "fails to clearly and conspicuously disclose that the person is not an FDIC-insured depository institution and that FDIC insurance only covers the failure of the FDIC-insured depository institution," and separately a statement about pass-through coverage that "fails to clearly and conspicuously disclose that certain conditions must be satisfied for pass-through deposit insurance coverage to apply."
So an app that says "FDIC insured" and nothing else is not complying with the rule, and the missing sentences are exactly the ones a customer needs.
The case that shows what the middle layer can do, told from the FDIC's own account. In its October 2024 proposed recordkeeping rule the FDIC set out the Synapse failure at length. Synapse Financial Technologies was a "middleware provider" whose software "bridged the information technology systems of fintech companies and IDIs," including "opening and managing deposit accounts, issuing debit and credit cards, and facilitating payments for customers." In those arrangements, the FDIC records, "fintech companies developed user interfaces and application logic, and importantly, maintained the ledgers of their customers, including the deposit amounts attributed to each individual customer."
Synapse filed for bankruptcy in late April 2024. In early May one partner bank "froze deposits that had been placed at the IDI through relationships with Synapse and the fintech companies that Synapse serviced," stating that it did so "because Synapse denied the IDI access to an essential system through which the IDI accessed information on end users, deposits, and transactions." Consumers could not reach their money for months. The FDIC's consumer assistance center received "more than a thousand inquiries, complaints, and concerns" from consumers about it. A bankruptcy trustee appointed in May 2024 "had difficulty obtaining access to Synapse's data, due in part to Synapse's termination of its employees, including employees who held credentials necessary to access systems." And the trustee "indicated that the deposits at the IDIs appear to be insufficient to cover the amounts owed by the fintech companies to their customers."
No insured bank failed. Deposit insurance was never triggered, because the event that triggers it did not happen. The loss of access came entirely from the records in the middle layer. That is the precise risk the two-species definition points at, and it is a different risk from the one deposit insurance is designed to cover.
It was not the first instance. The same FDIC document notes that in 2022 Voyager Digital "falsely represented that customer funds held with Voyager were insured by the FDIC up to $250,000 in the event of Voyager's failure, not just the failure of the IDI where Voyager deposited customer funds," and that when Voyager entered bankruptcy many customers could not access their accounts.
What the FDIC proposed, and what it has not done. The October 2024 rule would have required insured banks holding certain custodial deposit accounts to maintain records identifying the beneficial owners. Measured against the Code of Federal Regulations on 2026-08-28, no such part appears in title 12: it remains a proposal. What is in force is part 328 subpart B, above, and the ordinary deposit insurance rules.