Skip to main content

Security &
privacy

We take the security of your financial data seriously. Learn about the measures we have in place to protect your information.

Your financial data is among the most sensitive information you have. At Fynla, protecting it isn't just a technical requirement — it's a core value. We don't sell your data, we don't share it with third parties, and we don't earn commission from financial product providers. Every decision we make about how your data is stored, accessed, and protected is guided by one principle: your information belongs to you.

Authentication & account security

Multi-factor authentication

App-based TOTP authentication with backup recovery codes for secure account access.

Session management

View and revoke active sessions, with automatic logout after periods of inactivity.

Brute-force protection

Progressive lockout after repeated failed login attempts protects against unauthorised access.

Password security

Password breach checking and prevention of password reuse keeps your account secure.

Data protection & encryption

Encryption at rest

AES-256 encryption for sensitive financial fields including balances and account details.

Key management

Centralised key management with regular key rotation policies to maintain security.

Encrypted backups

All backups are encrypted with secure retention and deletion policies.

Secrets management

Production secrets are stored in secure vault services, never in code or configuration files.

Access control

Role-based access control

Distinct permission levels for different user types ensure appropriate access.

Principle of least privilege

Users and systems only have access to the minimum data required for their function.

Internal access logging

Every access to user data is logged and auditable for complete transparency.

Auditability & monitoring

Comprehensive audit logs

All login attempts, data access, and changes to financial plans are logged.

Immutable logs

Append-only, tamper-resistant log storage ensures audit trail integrity.

Suspicious activity alerts

Automated alerts for unusual behaviour such as unexpected login locations.

GDPR & privacy compliance

Right to erasure

Full deletion workflow including removal from backups after retention period.

Data minimisation

We only collect and store data that is necessary for your financial planning.

Consent tracking

Timestamped consent records for terms, privacy policy, and any marketing preferences.

Data export

Export all your data in a portable format at any time from your account settings.

API & application security

Rate limiting

Per-user and per-token rate limits protect against abuse and ensure fair usage.

Token security

Short-lived access tokens with automatic rotation maintain secure sessions.

Permission scoping

Read-only versus write permissions ensure tokens only have necessary access.

Business continuity

Disaster recovery

Defined recovery objectives with regular testing ensure rapid restoration.

Uptime monitoring

24/7 monitoring with automatic failover ensures continuous availability.

Important notice

Fynla is a financial planning tool designed to help you organise and visualise your financial information. It does not constitute regulated financial advice. The projections and calculations provided are for illustrative purposes only and should not be relied upon as the sole basis for financial decisions.

We recommend consulting with a qualified financial adviser for personalised advice tailored to your specific circumstances.

Have questions about our security practices?