Security & Compliance

FlowTrak is designed with security and privacy at its core. The following outlines the controls and policies we maintain to protect consumer data.

Access Control

Access to FlowTrak systems and data is role-based. Shared workspaces are gated by Firebase Authentication and can only be joined via invite codes. We follow the principle of least privilege and review access periodically.

Multi-Factor Authentication

FlowTrak supports device-level biometric authentication and requires verified Firebase Auth credentials. We enforce MFA for administrative access to backend systems.

Data Deletion & Retention

Users can delete their personal data and leave shared workspaces at any time. Workspace owners can remove members and delete shared data. Data is retained only as long as necessary to provide the service.

End-of-Life (EOL) Software Management

We monitor dependencies and third-party SDKs for EOL status. Security updates and patches are applied within our defined SLA, tracked through automated dependency scanning.

Vulnerability Scanning & Patching

We perform periodic security reviews and dependency vulnerability scans. Identified vulnerabilities are triaged and patched within a documented SLA.

Information Security Policy

FlowTrak maintains a documented Information Security Policy that covers access control, data protection, incident response, and acceptable use. The policy is reviewed and updated regularly.

Plaid Integration

Bank account connections are handled by Plaid. We never store online banking credentials. Access tokens are stored securely on the user's device using platform-native secure storage.