Flowarden is built around a simple constraint: we hold read-only financial data and no ability to move money.
Access to your bank
- Credentials are entered with a regulated aggregation provider, never with us.
- Tokens are read-only and scoped to transaction and balance data.
- Tokens are stored encrypted and are revocable by you at any time, from Flowarden or from your bank.
Data protection
- Encrypted in transit with modern TLS and encrypted at rest.
- Access controls enforced at the database level with row-level security, so authorisation does not depend on the interface behaving correctly.
- Privileged staff actions are written to an append-only audit log that staff cannot alter.
- Least privilege internally: access to production data is limited, justified, and logged.
Account-level controls
Two-factor authentication, session review and revocation, email alerts on security-relevant changes, and a full data export.
Payments
Card details are handled by our payment provider, which acts as merchant of record. Flowarden never sees or stores your card number.
Reporting a problem
Security reports are welcomed and triaged quickly — see the responsible disclosure article for the process and scope.