Information Security Policy
Security governance and technical controls.
1. Purpose
Draft for review. This document is an internal working template prepared to support commercial onboarding and institutional due diligence. It does not constitute legal advice and must be reviewed and approved by FLOWA PAY INC.'s legal and compliance functions before it is relied upon. FLOWA PAY INC. makes no representation that it holds any licence, authorisation or certification except the FINTRAC Money Services Business registration expressly stated in the Regulatory Disclosures.
This policy sets out how FLOWA PAY INC. protects the confidentiality, integrity and availability of its systems and data.
2. Controls
Controls include encryption, access management, network segmentation, logging and monitoring, vulnerability management and secure development practices.
3. Incident response
We maintain an incident-response capability to detect, contain, remediate and, where required, report security incidents.