Security

Security engineered like critical financial infrastructure.

Defense in depth, least-privilege access, and full auditability on every action. We publish only what is verified and are transparent about what is in progress.

Architecture

Defense in depth

Every layer — network, application, data — is independently hardened. Card data is handled in a segmented environment designed to PCI DSS.

  • Encryption in transit and at rest
  • Segmented card-data environment
  • Least-privilege, role-based access
  • Continuous monitoring and alerting
Perimeter · WAFEncryption at rest & in transit
Risk controls

Screening built into the flow

KYC/KYB, sanctions and PEP screening and adaptive fraud scoring run in onboarding and in-line on transactions, with a full audit trail on every decision.

  • In-line sanctions & PEP screening
  • Adaptive, ML-assisted fraud scoring
  • Case management and audit trails
  • Configurable risk rules and thresholds
1Identify2Screen3Score4Decide5Monitor
Standards

What we hold, and what's in progress

We never claim certifications we do not hold. This is our honest current status.

Verified
🍁

FINTRAC MSB

FLOWA PAY INC. registered Money Services Business, Canada. Reg. no. C100000902.

In progress
🛡️

PCI DSS

Card-data environment engineered to PCI DSS. Formal attestation targeted pre-launch.

In progress
🔐

SOC 2 · ISO 27001

Controls aligned to SOC 2 and ISO 27001; independent audit planned.

Aligned
🌍

GDPR

Privacy-by-design data handling aligned to GDPR and applicable law.

Statuses reflect our current position and will be updated as attestations complete.

Talk to our security team

Request our security overview and due-diligence pack for institutional review.