Security you can actually verify.
We separate what's live today from what's on the roadmap - no badge claims more than the platform delivers. Here's exactly how FlowAcq treats your traffic.
What's protecting you now
- Card data is tokenized - FlowAcq stores tokens, not raw PANs.
- HMAC-SHA256 signed webhooks with per-endpoint secrets you can rotate.
- Pre-authorization velocity rules and global blocklists screen traffic.
- KYB merchant approval gates live access; sandbox needs no money at risk.
- Every sensitive action writes an immutable audit row.
- Encryption in transit (TLS) and at rest for stored records.
What we're building next
- Behavioral and device-based fraud scoring beyond velocity rules.
- Formal compliance attestations (we don't claim certifications we don't hold).
- Granular team roles and scoped API-key permissions.
- Customer-managed data retention and export controls.
- Settlement import, reconciliation review, and finance reporting.
Data handling
FlowAcq is built to stay out of your PCI scope where possible: sensitive instrument data is exchanged for tokens, and only those tokens flow through the orchestration layer. Operational records - transactions, deliveries, audit events - are stored to power your dashboard and reconciliation.
Webhook integrity
Outbound events are signed so your backend can prove they came from FlowAcq and weren't tampered with. Deliveries are logged with the exact payload and response, and any event can be replayed.
Access & approval
Live processing is dependent behind KYB review. Until a business is approved, it operates in sandbox - the same API surface, with no funds at risk.
Have a security or compliance question? Reach our team.