Security Overview
Security is foundational to everything we build. As an FCA-authorised open banking provider operating at the intersection of financial data and payment infrastructure, we apply defence-in-depth across every layer of our platform. Our security programme is governed by our Information Security Management System (ISMS), certified to ISO 27001, and shaped by FCA SYSC requirements, the UK Open Banking Security Profile, and leading industry frameworks including NIST CSF and OWASP.
Certifications & Standards
Data Encryption
In transit
- All data in transit is encrypted using TLS 1.2 minimum, TLS 1.3 preferred. TLS 1.0 and 1.1 are disabled across all endpoints.
- HTTP Strict Transport Security (HSTS) with a minimum 12-month max-age is enforced on all domains.
- Certificate pinning is applied for our mobile SDKs. Certificates are rotated well in advance of expiry using automated tooling.
- All API traffic uses forward secrecy cipher suites (ECDHE), preventing retroactive decryption if a key is later compromised.
At rest
- All data at rest is encrypted using AES-256-GCM.
- Database encryption keys are managed by a dedicated Hardware Security Module (HSM) with strict access controls and audit logging.
- Encryption keys are rotated on a defined schedule; emergency key rotation procedures are documented and tested.
- Backups are encrypted with separate keys from primary data stores and stored in geographically separate, secure locations.
Key management
- Cryptographic key lifecycle (generation, distribution, storage, rotation, and destruction) is governed by our Key Management Policy aligned to NIST SP 800-57.
- No long-lived plaintext secrets are stored in code repositories, CI/CD systems, or configuration files — all secrets are injected via a secrets management platform with full audit trails.
Open Banking Security
Our open banking integrations conform to the UK Open Banking Security Profile, which is built on the Financial-grade API (FAPI) 2.0 standard developed by the OpenID Foundation. This ensures the highest level of security for consent flows and API access.
- OAuth 2.0 + PKCE: all customer authentication flows use OAuth 2.0 with Proof Key for Code Exchange to prevent authorisation code interception attacks.
- Pushed Authorisation Requests (PAR): authorisation parameters are pushed directly to the bank's authorisation server, eliminating exposure via browser redirects.
- JWT Secured Authorisation Response Mode (JARM): authorisation responses are signed JWTs, preventing tampering.
- Mutual TLS (mTLS): sender-constrained access tokens prevent token replay attacks; our eIDAS-compliant certificate is used for bank API authentication.
- Strong Customer Authentication (SCA): we fully support and enforce SCA as required by the PSRs, ensuring customers authenticate directly with their bank via approved SCA methods.
- Credential-free: we never receive, request, or store end-users' online banking usernames, passwords, or one-time passcodes.
- Consent scoping: API tokens are strictly scoped to the permissions granted in the consent. Our infrastructure enforces scope limits at the gateway level, rejecting any request that exceeds the granted scope.
Infrastructure & Access Controls
Cloud infrastructure
- Hosted in UK-based data centres that are ISO 27001, SOC 2 Type II, and PCI DSS certified.
- Production, staging, and development environments are strictly segregated at the network and IAM level.
- Infrastructure is defined as code (IaC) with all changes reviewed, approved, and deployed via a secure CI/CD pipeline. No manual changes to production infrastructure are permitted.
- DDoS mitigation is applied at the network edge using an always-on scrubbing service with automatic failover.
Access controls
- Zero-trust architecture: no implicit trust based on network location. All access requests are authenticated, authorised, and continuously verified.
- Role-based access control (RBAC): least-privilege access to all systems. Access rights are reviewed quarterly and revoked immediately on role change or offboarding.
- Multi-factor authentication (MFA): mandatory for all staff on all corporate systems, cloud consoles, and production access paths — no exceptions.
- Privileged access management: just-in-time privileged access with full session recording and audit trails for any production access.
- Background checks: all employees and contractors with access to production systems or sensitive data undergo enhanced DBS checks and employment verification before onboarding.
Monitoring & detection
- 24/7 Security Operations Centre (SOC) monitoring with SIEM aggregating logs across all infrastructure and application layers.
- Anomaly detection and behavioural analytics for API traffic to identify unusual patterns, credential stuffing, and data exfiltration attempts.
- Immutable audit logs retained for 12 months online and 5 years archived; tamper-evident using cryptographic chaining.
Penetration Testing
We commission independent, CREST-certified penetration tests of our infrastructure, APIs, and web applications on the following schedule:
- Quarterly: external network and API penetration tests by an independent CREST-accredited provider.
- Annually: full-scope red team exercise simulating an advanced persistent threat (APT) actor, including social engineering and physical security elements.
- On significant change: targeted security assessments for any major feature release, infrastructure migration, or significant architectural change.
All critical and high findings are remediated within 24 hours and 7 days respectively from identification. Remediation is verified by re-test before the findings are closed. We maintain a remediation register with full audit trails for FCA supervisory review.
Security test results are reviewed by our Board-level Technology & Risk Committee quarterly.
Incident Response
We maintain a documented, tested Incident Response Plan (IRP) aligned to NIST SP 800-61 and FCA operational resilience requirements (PS21/3). Our response process follows the phases below:
In the event of a personal data breach, we will notify the ICO within 72 hours as required by UK GDPR Article 33, and affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
We publish a post-incident summary on our status page for any incidents that affect service availability or customer data, within 5 business days of resolution.
Responsible Vulnerability Disclosure
We operate a Responsible Disclosure Programme and welcome security researchers who report vulnerabilities in good faith. We commit to:
- Acknowledging your report within 3 business days;
- Providing a substantive update within 10 business days;
- Notifying you when the vulnerability is remediated;
- Not pursuing legal action against researchers who comply with this policy;
- Publicly acknowledging your contribution (with your consent) in our Hall of Fame.
In scope
- All endpoints under reflowzone.io and api.reflowzone.io
- Our mobile SDKs (iOS and Android)
- Our developer dashboard
Out of scope
- Denial of service (DoS/DDoS) attacks
- Social engineering of Reflow staff or customers
- Physical security testing
- Automated scanning without prior permission
- Third-party bank APIs (report these to the relevant bank)
To report a vulnerability, email security@reflowzone.io with a detailed description, steps to reproduce, potential impact, and any supporting evidence. Please encrypt sensitive reports using our PGP key, available on our developer docs page.
Supplier Security
We apply rigorous security standards to all third-party suppliers and sub-processors that handle data or provide services that could affect the security of our platform.
- All critical suppliers undergo security due diligence before onboarding, including review of their certifications, pen test results, and security questionnaires (based on SIG Lite/Full or equivalent).
- Data Processing Agreements (DPAs) are in place with all sub-processors, including security obligations and audit rights.
- Critical suppliers are subject to annual re-assessment; any material change in their security posture triggers an immediate review.
- Supplier access to Reflow systems is governed by least-privilege principles, time-limited, and subject to full audit logging.
- We maintain a register of critical suppliers and assess supply chain concentration risk as part of our operational resilience planning.
Security Tips for Customers
Securing your Reflow integration is a shared responsibility. Here's how to keep your account and API usage secure:
- Protect your API keys: treat API keys like passwords. Never commit them to public repositories (use secret scanning like GitHub's built-in detection). Rotate them immediately if you suspect compromise.
- Use environment variables: store API keys in environment variables or a secrets manager — never hard-code them in source code.
- Enable MFA: use multi-factor authentication on your Reflow dashboard account and all accounts in your organisation that have access.
- Scope your API keys: create API keys with only the permissions your application needs — use read-only keys for data access where payment initiation is not required.
- Verify webhooks: always validate webhook signatures using our HMAC-SHA256 signing secret before processing webhook payloads.
- Monitor your usage: set up usage alerts in your dashboard and investigate any unexpected API call patterns promptly.
- Keep dependencies updated: if using our SDK, update to the latest version promptly when security patches are released.
- Restrict IP addresses: use our IP allowlisting feature to restrict API key usage to known IP ranges.
If you believe your API keys or account have been compromised, contact us immediately at security@reflowzone.io or revoke the affected keys directly in your dashboard.