Security & Trust
Trust is built in the details.
A financing relationship involves sensitive financial information. This page sets out the security, privacy and resilience topics that matter, the standards that apply and how to request documentation for your own review.
This website
How this website protects you.
These safeguards apply to www.cashflowowner.com today.
-
Encrypted connections
This website is served only over HTTPS, so pages you view are encrypted in transit.
-
No tracking
This website does not use advertising pixels, third party analytics or tracking cookies.
-
One place to sign in
Client sign in happens only at app.cashflowowner.com. Always confirm that address before entering your credentials.
-
Documents stay out of email
Financial documents belong in the secure application or your client account, not in email attachments.
Standards and practices
Assurance and compliance
Independent attestations, certifications and the legal frameworks that govern personal data.
-
SOC 2
An independent attestation, performed under AICPA standards, on how a service organization designs and operates controls for security, availability, processing integrity, confidentiality and privacy. A SOC 2 report names the organization and systems it covers and the period it examined.
-
ISO/IEC 27001
The international standard for an information security management system. Certification is issued by an accredited certification body for a defined scope, and the scope is stated on the certificate.
-
GDPR
The European Union’s General Data Protection Regulation governs how personal data about individuals in the EU is processed. It is a legal framework rather than a certification, and it applies based on whose data is processed and why.
-
Data residency
Where client data is stored and processed. For some businesses and jurisdictions, location determines which laws apply and which contractual commitments are required.
Standards and practices
Protection
The controls that keep financial information confidential and available only to the right people.
-
Data protection
How personal and financial information is collected, used, retained and shared, and the choices and rights you have over it.
-
Encryption
Protection of information while it travels between you and us and while it is stored, including how encryption keys are managed.
-
Identity and access
How sign in is secured, how access to client information is limited to people with a business need, and how that access is reviewed over time.
-
Infrastructure security
How the systems behind the client experience are hosted, monitored, patched and protected, and how environments are separated.
Standards and practices
Resilience and transparency
How service continues through disruption, and how you can verify what we say.
-
Business continuity
How services and data are protected against outages, and how they are recovered within defined objectives if something goes wrong.
-
Security documentation
Reports, policies and questionnaire responses that support your own due diligence when you evaluate a financial partner.
Security documentation
Request security documentation.
Security reviews are a normal part of choosing a financial partner. Request reports, policies and questionnaire responses to support your due diligence.
Online documentation requests are opening soon.
Ready when you are.
Start with a secure digital application. We will review your business and talk through the structure that fits.