Security engineered like critical financial infrastructure.
Defense in depth, least-privilege access, and full auditability on every action. We publish only what is verified and are transparent about what is in progress.
Defense in depth
Every layer — network, application, data — is independently hardened. Card data is handled in a segmented environment designed to PCI DSS.
- Encryption in transit and at rest
- Segmented card-data environment
- Least-privilege, role-based access
- Continuous monitoring and alerting
Screening built into the flow
KYC/KYB, sanctions and PEP screening and rule-based transaction risk controls run in onboarding and in-line on payments, with a full audit trail on every decision.
- In-line sanctions & PEP screening
- Rule-based transaction risk controls and velocity limits
- Case management and audit trails
- Configurable risk rules and thresholds
How the platform is protected
These are the controls in place today. Where something is planned rather than complete, it is listed under Standards below as in progress.
Payment security
Card data is captured in a Flowa Pay-controlled payment surface on hosted and embedded integrations, so it does not transit or rest in merchant systems.
Encryption
Data is encrypted in transit with current TLS and at rest in the platform's data stores. Keys are managed server-side and rotated.
Tokenization
Card numbers are exchanged for tokens at capture. Merchants store and charge the token; the sensitive value stays in the payment environment.
PCI-related architecture
The card-data environment is segmented from general application infrastructure and engineered to PCI DSS. Formal attestation is in progress, and we do not describe it as complete.
Access controls
Role-based access with least privilege and segregation of duties. Production access is restricted, justified and logged.
Authentication
Multi-factor authentication for platform accounts, scoped API credentials per environment, and 3-D Secure 2 for cardholder authentication where it applies.
API security
Server-side-only credentials, signed webhooks, idempotency on mutating calls, rate limiting and request validation on every endpoint.
Monitoring
Continuous monitoring of availability, latency, error rates and provider health, with alerting on anomalies and on degraded routes.
Data protection
Privacy-by-design handling, data minimisation, defined retention and deletion, and documented bases for processing under applicable law.
Operational security
Change control, environment separation, dependency and vulnerability management, and periodic review of access and configuration.
Incident management
A documented incident-response process with defined severities, escalation paths, customer notification and post-incident review.
What we hold, and what's in progress
We never claim certifications we do not hold. This is our honest current status.
FINTRAC MSB
FLOWA PAY INC. registered Money Services Business, Canada. Reg. no. C100000902.
PCI DSS
Card-data environment engineered to PCI DSS. Formal attestation targeted pre-launch.
SOC 2 · ISO 27001
Controls aligned to SOC 2 and ISO 27001; independent audit planned.
GDPR
Privacy-by-design data handling aligned to GDPR and applicable law.
Statuses reflect our current position and will be updated as attestations complete.
Talk to our security team
Request our security overview and due-diligence pack for institutional review.