Finawo reads sensitive money data, so we treat it that way. Here is how it is protected, stated plainly, with no claims we cannot back.
Bank connections run through Plaid, the same layer thousands of finance apps and banks already trust. You authenticate with your bank, not with us. Finawo never sees or stores your online banking username and password.
The access tokens that let us read your accounts are encrypted with AES-256-GCM before they ever touch the database. They are decrypted only in memory, only when a sync runs.
Your login session is a signed token in a cookie that JavaScript cannot read and that is only sent to Finawo. In production it travels only over HTTPS.
Every workspace has owners, admins, staff, an accountant and viewers. Read-only roles cannot change your books, and every request is checked against your membership before any data is returned.
Changes to your ledger, from a manual edit to an assistant action, are written to an audit log with who did it and when, so nothing happens to your books without a record.
Finawo reads your financial data to give you a picture. It does not move your money. There is no payment rail here to compromise.
We are early, and we would rather tell you what is true today than claim a certification we have not earned. Formal compliance work is on our roadmap. If you have a security question before then, reach out and a real person will answer.
Reach out and a real person will answer, before you connect a single account.