FlowTrak is designed with security and privacy at its core. The following outlines the controls and policies we maintain to protect consumer data.
Access to FlowTrak systems and data is role-based. Shared workspaces are gated by Firebase Authentication and can only be joined via invite codes. We follow the principle of least privilege and review access periodically.
FlowTrak supports device-level biometric authentication and requires verified Firebase Auth credentials. We enforce MFA for administrative access to backend systems.
Users can delete their personal data and leave shared workspaces at any time. Workspace owners can remove members and delete shared data. Data is retained only as long as necessary to provide the service.
We monitor dependencies and third-party SDKs for EOL status. Security updates and patches are applied within our defined SLA, tracked through automated dependency scanning.
We perform periodic security reviews and dependency vulnerability scans. Identified vulnerabilities are triaged and patched within a documented SLA.
FlowTrak maintains a documented Information Security Policy that covers access control, data protection, incident response, and acceptable use. The policy is reviewed and updated regularly.
Bank account connections are handled by Plaid. We never store online banking credentials. Access tokens are stored securely on the user's device using platform-native secure storage.