Built to be trusted with money
We're a small, early-stage team - which is exactly why we'd rather tell you precisely what's true today than borrow the authority of certifications we haven't earned yet.
We never see your banking credentials
Bank connections run over PSD2 Open Banking rails through regulated aggregation infrastructure. FinSync never stores, sees, or handles your online banking username or password - access is a revocable, scoped token, not a login you hand over.
Every action is org-scoped, by design
Access control is enforced at the token level - every request carries a signed claim identifying which organization it belongs to, checked before any data is read or written. There is no code path that lets one organization see another's data.
A real, auditable ledger underneath
Every transaction posts a balanced double-entry journal entry against a proper chart of accounts. Nothing is a balance overwritten in place - the full history is there to audit, reconcile, and reverse correctly if it ever needs to be.
Encrypted in transit and at rest
All traffic runs over TLS. Data at rest is encrypted. Payment initiation requires an authenticated, approval-gated request - there is no path to move money that skips the approval policy your organization configures.
Where we stand today
Bank connectivity runs over regulated Open Banking rails, not screen scraping.
Built around EU data protection principles, with EU data residency.
On our roadmap as we move out of private beta - not yet certified, and we won't claim otherwise.
Found a problem?
If you think you've found a security issue, we want to hear about it before anyone else does. Email us directly and we'll respond personally - there's no bug bounty program yet, but every report gets read by someone who can actually fix it.
security@finsync.se