Security overview

Last updated 25 August 2026

Flowarden is built around a simple constraint: we hold read-only financial data and no ability to move money.

Access to your bank

- Credentials are entered with a regulated aggregation provider, never with us.

- Tokens are read-only and scoped to transaction and balance data.

- Tokens are stored encrypted and are revocable by you at any time, from Flowarden or from your bank.

Data protection

- Encrypted in transit with modern TLS and encrypted at rest.

- Access controls enforced at the database level with row-level security, so authorisation does not depend on the interface behaving correctly.

- Privileged staff actions are written to an append-only audit log that staff cannot alter.

- Least privilege internally: access to production data is limited, justified, and logged.

Account-level controls

Two-factor authentication, session review and revocation, email alerts on security-relevant changes, and a full data export.

Payments

Card details are handled by our payment provider, which acts as merchant of record. Flowarden never sees or stores your card number.

Reporting a problem

Security reports are welcomed and triaged quickly — see the responsible disclosure article for the process and scope.

// STILL NEED A HAND?

We reply to every message, usually within a business day.

Contact support