Security engineered like critical financial infrastructure.
Defense in depth, least-privilege access, and full auditability on every action. We publish only what is verified and are transparent about what is in progress.
Defense in depth
Every layer — network, application, data — is independently hardened. Card data is handled in a segmented environment designed to PCI DSS.
- Encryption in transit and at rest
- Segmented card-data environment
- Least-privilege, role-based access
- Continuous monitoring and alerting
Screening built into the flow
KYC/KYB, sanctions and PEP screening and adaptive fraud scoring run in onboarding and in-line on transactions, with a full audit trail on every decision.
- In-line sanctions & PEP screening
- Adaptive, ML-assisted fraud scoring
- Case management and audit trails
- Configurable risk rules and thresholds
What we hold, and what's in progress
We never claim certifications we do not hold. This is our honest current status.
FINTRAC MSB
FLOWA PAY INC. registered Money Services Business, Canada. Reg. no. C100000902.
PCI DSS
Card-data environment engineered to PCI DSS. Formal attestation targeted pre-launch.
SOC 2 · ISO 27001
Controls aligned to SOC 2 and ISO 27001; independent audit planned.
GDPR
Privacy-by-design data handling aligned to GDPR and applicable law.
Statuses reflect our current position and will be updated as attestations complete.
Talk to our security team
Request our security overview and due-diligence pack for institutional review.