Security and Data Protection at FlowState Financial

Last Updated: July 28, 2026

As a financial services firm handling sensitive business data, payroll records, and banking information, security is foundational to everything we do. This page explains how we protect your data, the standards we follow, and what you can expect from our security practices.

Our Security Commitment

FlowState Financial implements administrative, technical, and physical safeguards designed to protect client financial data from unauthorized access, disclosure, alteration, or destruction. Our security program is built around the core principles of confidentiality, integrity, and availability.

Infrastructure and Hosting Security

  • SOC 2 Compliant Hosting: Our cloud infrastructure providers maintain SOC 2 Type II compliance, verified through annual third-party audits.
  • 256-bit SSL/TLS Encryption: All data transmitted between your browser, our portal, and integrated platforms is encrypted using industry-standard TLS 1.2+ protocols.
  • Data at Rest Encryption: All stored documents, financial records, and client files are encrypted at rest using AES-256 encryption.
  • Daily Backups: Encrypted backups are performed daily and stored in geographically redundant, secure off-site facilities.
  • Network Security: Firewalls, intrusion detection systems, and regular vulnerability scanning protect our infrastructure.

Access Controls and Authentication

  • Multi-Factor Authentication (MFA): MFA is enforced on all financial platform accounts (QuickBooks Online, Gusto, Bill.com, banking portals) accessed on behalf of clients.
  • Role-Based Access Control (RBAC): Team members access only the systems and client data required for their specific responsibilities. Access is reviewed quarterly.
  • Least Privilege Principle: Administrative access is restricted to named senior personnel. No shared accounts or generic credentials.
  • Quarterly Access Reviews: User access permissions are reviewed every 90 days. Former team member access is revoked within 24 hours of departure.
  • Password Policy: All team members are required to use strong, unique passwords managed through an enterprise password manager.

Client Data Handling

  • Encrypted Client Portal: Sensitive documents are shared through our encrypted portal — never via email or unencrypted file-sharing services.
  • 7-Year Document Retention: Client financial records are retained for 7 years in accordance with IRS requirements, then securely destroyed.
  • Data Segregation: Each client’s data is logically segregated within our systems. Cross-client data access is not possible for team members.
  • No Data Resale: We never sell, share, or monetize client data. Your financial information is used solely to deliver the services you have engaged us for.

Platform-Specific Security

When we access your financial platforms on your behalf, we follow these protocols: credentials are stored in an encrypted password manager — never in spreadsheets, emails, or chat messages; access is granted through dedicated user roles with minimum necessary permissions; bank feed connections use read-only access where possible; payment and approval actions require your explicit authorization through platform workflows; and all platform activity is logged and auditable.

Team Training and Policies

  • Security Onboarding: All team members complete security training before accessing client systems
  • Annual Refresher Training: Security awareness training is repeated annually, covering phishing, social engineering, data handling, and incident response
  • Confidentiality Agreements: All team members sign NDAs and confidentiality agreements covering client data
  • Clean Desk Policy: No client data is printed or stored on unencrypted physical media
  • Remote Work Security: All team members use encrypted connections (VPN), device encryption, and screen lock policies when working remotely

Incident Response

In the unlikely event of a data breach or security incident, our incident response plan includes immediate containment and investigation within 1 hour of detection, client notification within 48 hours of confirmed breach affecting client data, full transparency on what data was affected and what steps are being taken, engagement of third-party forensic experts if necessary, and post-incident review and preventive measures implemented within 30 days.

Compliance Frameworks

Our security practices are aligned with the following frameworks and standards: SOC 2 Type II (our hosting providers maintain SOC 2 compliance), IRS Publication 4557 (Safeguarding Taxpayer Data guidelines), GLBA (Gramm-Leach-Bliley Act financial information safeguarding requirements), CCPA (California Consumer Privacy Act consumer data privacy rights), and PCI DSS (Payment card industry data security standards applicable to payment processing).

Your Responsibilities

Security is a shared responsibility. To help protect your data, we ask that you use strong, unique passwords for all financial platform accounts, enable MFA on all accounts you grant us access to, notify us immediately if you suspect unauthorized access to any account, never share login credentials via email, chat, or unsecured channels, keep your contact information current so we can reach you about security matters, and not submit confidential data (passwords, SSN, bank credentials) through our website contact form.

Secure Document Submission

If you need to share sensitive documents with us (tax returns, bank statements, payroll records), please use our encrypted client portal. After your initial consultation, we will provision a secure portal account for document exchange. Do not send sensitive documents via email.

Questions About Security

If you have questions about our security practices, need to report a security concern, or would like to discuss our security posture before engaging our services, contact us at:

FlowState Financial — Security Team
Email: info@flowstatesfinancial.com
Phone: (213) 429-9003

We are happy to discuss our security practices in detail during your initial consultation or at any point during our engagement.

Related Policies