Professional Grade Security

Security & Sovereignty

We operate NivoaFlow with a security-first mindset. Your financial history is encrypted, isolated, and protected using industry-standard practices.

Encryption at Rest

All financial ledger data is encrypted at rest using industry-standard encryption. Keys are managed by our cloud infrastructure with automatic rotation policies.

RLS Isolation

Row-Level Security (RLS) enforces data isolation at the database layer, preventing cross-user data access through technical controls.

Audit Transparency

Sensitive system events are logged to our audit system for security monitoring, including balance and currency changes, household sharing activity, and unauthorised access attempts. Ask us any time and we will provide your security history.

Technical Infrastructure

NivoaFlow is hosted on enterprise-grade infrastructure provided by Google Cloud Platform (GCP) and Supabase. Our architecture is designed with security in mind:

  • Network Isolation: Database access is restricted through managed service accounts and private networking where available.
  • API Security: All API requests pass through security middleware enforcing CORS policies, CSRF protection, and rate limits.
  • Dependency Management: Automated vulnerability scanning via Dependabot helps identify and remediate security risks in dependencies.

Data Sovereignty Pledge

Access Controls

NivoaFlow limits staff access to your financial data through technical controls including Row-Level Security. Our support tools use anonymized identifiers for troubleshooting where possible.

Instant Data Portability

You have the right to a clean exit. Our "Export Cabinet" feature generates a machine-readable JSON file of your entire history with zero friction. You own your data; we are simply its custodians.

Audit Logging

Security events including password changes, data deletions, and household invitations are recorded in our audit system and retained according to our data retention policy.

Account Deletion

When you delete your account, we initiate a full deletion process that removes your data from production systems and backup cycles according to our data retention schedule.

Authentication & Identity

Identity is the first line of defense. We implement modern best practices for account security:

  • Password Hashing: Passwords are hashed using bcrypt, an industry-standard algorithm designed to be computationally expensive and resistant to brute-force attacks.
  • Session Management: Secure session tokens are stored in HTTP-only cookies with appropriate security attributes to prevent common web attacks.
  • Multi-Factor Authentication: Optional TOTP-based MFA adds an extra layer of security to your account.

Incident Response

In the event of a suspected security event, our response team follows a formal incident lifecycle (Preparation, Identification, Containment, Eradication, Recovery, and Lessons Learned).

We communicate platform-wide technical issues or security notifications to affected users via email and in-app notices.

Vulnerability Reporting

Are you a security researcher? We welcome your submissions. Please follow our Responsible Disclosure guidelines.

security@nivoaflow.com