Security

Security engineered like critical financial infrastructure.

Defense in depth, least-privilege access, and full auditability on every action. We publish only what is verified and are transparent about what is in progress.

Architecture

Defense in depth

Every layer — network, application, data — is independently hardened. Card data is handled in a segmented environment designed to PCI DSS.

  • Encryption in transit and at rest
  • Segmented card-data environment
  • Least-privilege, role-based access
  • Continuous monitoring and alerting
Perimeter · WAFEncryption at rest & in transit
Risk controls

Screening built into the flow

KYC/KYB, sanctions and PEP screening and rule-based transaction risk controls run in onboarding and in-line on payments, with a full audit trail on every decision.

  • In-line sanctions & PEP screening
  • Rule-based transaction risk controls and velocity limits
  • Case management and audit trails
  • Configurable risk rules and thresholds
1Identify2Screen3Score4Decide5Monitor
Controls

How the platform is protected

These are the controls in place today. Where something is planned rather than complete, it is listed under Standards below as in progress.

Payment security

Card data is captured in a Flowa Pay-controlled payment surface on hosted and embedded integrations, so it does not transit or rest in merchant systems.

Encryption

Data is encrypted in transit with current TLS and at rest in the platform's data stores. Keys are managed server-side and rotated.

Tokenization

Card numbers are exchanged for tokens at capture. Merchants store and charge the token; the sensitive value stays in the payment environment.

PCI-related architecture

The card-data environment is segmented from general application infrastructure and engineered to PCI DSS. Formal attestation is in progress, and we do not describe it as complete.

Access controls

Role-based access with least privilege and segregation of duties. Production access is restricted, justified and logged.

Authentication

Multi-factor authentication for platform accounts, scoped API credentials per environment, and 3-D Secure 2 for cardholder authentication where it applies.

API security

Server-side-only credentials, signed webhooks, idempotency on mutating calls, rate limiting and request validation on every endpoint.

Monitoring

Continuous monitoring of availability, latency, error rates and provider health, with alerting on anomalies and on degraded routes.

Data protection

Privacy-by-design handling, data minimisation, defined retention and deletion, and documented bases for processing under applicable law.

Operational security

Change control, environment separation, dependency and vulnerability management, and periodic review of access and configuration.

Incident management

A documented incident-response process with defined severities, escalation paths, customer notification and post-incident review.

Standards

What we hold, and what's in progress

We never claim certifications we do not hold. This is our honest current status.

Verified

FINTRAC MSB

FLOWA PAY INC. registered Money Services Business, Canada. Reg. no. C100000902.

In progress

PCI DSS

Card-data environment engineered to PCI DSS. Formal attestation targeted pre-launch.

In progress

SOC 2 · ISO 27001

Controls aligned to SOC 2 and ISO 27001; independent audit planned.

Aligned

GDPR

Privacy-by-design data handling aligned to GDPR and applicable law.

Statuses reflect our current position and will be updated as attestations complete.

Talk to our security team

Request our security overview and due-diligence pack for institutional review.