Security
Your financial data is handled with bank-grade controls
Remitloom never stores bank credentials, uses read-only API access, encrypts data at rest and in transit, and maintains the access audit trail your security team requires.
Encryption at rest
Encryption in transit
Bank access scope
We read. We never write to your bank.
Remitloom connects to bank feeds via Plaid or direct open-banking APIs with a read-only token scope. That means Remitloom can pull transaction data but cannot initiate transfers, move funds, or modify any bank account settings. This is enforced at the API token level, not just a policy.
- OAuth tokens with read-only transaction scope only
- No bank credentials stored at any time
- Token rotation every 90 days
Built for finance teams that face audits
Every control below was designed to satisfy what your auditors, IT security team, or compliance officer will ask for.
AES-256 encryption at rest
All transaction data, reconciliation workpapers, and close packages are encrypted at rest using AES-256. Encryption keys are managed per-tenant with automatic rotation.
TLS 1.3 in transit
All data in transit is protected with TLS 1.3. Older cipher suites are disabled at the load balancer level. Certificate pinning is enforced for our mobile and API clients.
SSO and MFA
Single sign-on via SAML 2.0 and OIDC is supported on Growth and Finance plans. Multi-factor authentication is enforced for all user accounts with no opt-out for admin roles.
Role-based access control
Finance teams have fine-grained RBAC: preparers can reconcile, reviewers can approve, read-only roles can view dashboards. No user can access more data than their role permits.
Complete audit log
Every action in Remitloom is logged with user identity, timestamp, IP address, and action details. Audit logs are immutable, retained for 7 years, and exportable on demand.
SOC 2 Type II controls
Remitloom is built to SOC 2 Type II security and availability criteria. Our security controls are reviewed annually and we share our latest report under NDA upon request.
Enterprise-grade infrastructure
Talk to our team about your security requirements
We share our security documentation, answer IT and compliance questions, and can schedule a technical review call before you sign up.