Security

Your financial data is handled with bank-grade controls

Remitloom never stores bank credentials, uses read-only API access, encrypts data at rest and in transit, and maintains the access audit trail your security team requires.

AES-256

Encryption at rest

TLS 1.3

Encryption in transit

Read-only

Bank access scope

Data access

We read. We never write to your bank.

Remitloom connects to bank feeds via Plaid or direct open-banking APIs with a read-only token scope. That means Remitloom can pull transaction data but cannot initiate transfers, move funds, or modify any bank account settings. This is enforced at the API token level, not just a policy.

  • OAuth tokens with read-only transaction scope only
  • No bank credentials stored at any time
  • Token rotation every 90 days
Diagram showing read-only data flow from bank feeds through Remitloom's encrypted pipeline to the reconciliation engine
Security controls

Built for finance teams that face audits

Every control below was designed to satisfy what your auditors, IT security team, or compliance officer will ask for.

AES-256 encryption at rest

All transaction data, reconciliation workpapers, and close packages are encrypted at rest using AES-256. Encryption keys are managed per-tenant with automatic rotation.

TLS 1.3 in transit

All data in transit is protected with TLS 1.3. Older cipher suites are disabled at the load balancer level. Certificate pinning is enforced for our mobile and API clients.

SSO and MFA

Single sign-on via SAML 2.0 and OIDC is supported on Growth and Finance plans. Multi-factor authentication is enforced for all user accounts with no opt-out for admin roles.

Role-based access control

Finance teams have fine-grained RBAC: preparers can reconcile, reviewers can approve, read-only roles can view dashboards. No user can access more data than their role permits.

Complete audit log

Every action in Remitloom is logged with user identity, timestamp, IP address, and action details. Audit logs are immutable, retained for 7 years, and exportable on demand.

SOC 2 Type II controls

Remitloom is built to SOC 2 Type II security and availability criteria. Our security controls are reviewed annually and we share our latest report under NDA upon request.

Infrastructure

Enterprise-grade infrastructure

AWS multi-region deployment

Remitloom runs on AWS with automatic failover across availability zones. Your data is replicated to a secondary region in real time for disaster recovery.

Daily encrypted backups

All customer data is backed up daily to encrypted storage with point-in-time recovery capability up to 30 days. Backup integrity is tested automatically each week.

99.9% uptime SLA

We commit to 99.9% uptime for all paid plans. The nightly reconciliation run includes automatic retry logic so a temporary outage doesn't cause a missed run.

Security questions?

Talk to our team about your security requirements

We share our security documentation, answer IT and compliance questions, and can schedule a technical review call before you sign up.