In fact, our frontend plugin was also called "Connect".
As an end user, it sounds like you will take my credentials for my utility provider, log into their website with those credentials, extract my data, store it in a normalized form in your DB, and expose it through your REST API.
Is this true?
If so, while you are logged in, you will also have access to financial information (e.g. bank account information, billing info, etc.). This is pretty sensitive data. What kind of guarantees are you making about not touching that data?
(All this assumes that my model for how Pelm works is true. Apologies if it isn't.)