Trust & reliability

Security at NoboFlow

Practical security, applied consistently — across our website, our products, and the way we work with the people who find our weaknesses.

How we think about security

Security at NoboFlow is not a feature bolted on at the end — it is one of the shared standards every NoboFlow product is built on, alongside design and reliability. We aim for practices that are proportionate, verifiable and improving over time, and we would rather be measured by how we respond to problems than by claims we cannot support.

Practices we follow

Encryption

  • Data is encrypted in transit between your devices and our services using TLS.
  • Product data at rest is encrypted using industry-standard mechanisms provided by our infrastructure.

Access control

  • Employee access to production systems follows least privilege and is reviewed regularly.
  • Administrative access requires authentication and is logged.

Secure development

  • Changes to our products go through peer review before release.
  • Dependencies are monitored for known vulnerabilities and patched in a prioritised way.
  • We align our practices with recognised industry frameworks and strengthen them as we grow.

Resilience

  • Product data is backed up, and restoration is tested.
  • Infrastructure and application logs are monitored for anomalies.

Product security

The MY Finance application (finance.noboflow.com) is a dedicated, separately hosted service. It runs under the same NoboFlow security standards described here, with account-level protections such as encrypted transport, per-user access separation and in-product session security. Product-specific security details are available inside the application or on request.

Vulnerability disclosure

We welcome reports from security researchers and users, and we commit to treating them seriously and respectfully.

How to report

  • Write to security@noboflow.com.
  • Include a description of the issue, the steps or request needed to reproduce it, and any affected URLs or accounts.
  • If possible, include proof-of-concept details that help us verify the issue quickly.

What you can expect from us

  • Acknowledgement of your report within 3 business days.
  • Communication as we investigate, remediate and verify a fix.
  • Good faith. We will not pursue legal action against researchers who report vulnerabilities responsibly, respect user privacy, avoid service disruption, and give us reasonable time to fix issues before public disclosure.

What we ask of you

  • Use only your own test accounts and data.
  • Do not access, modify or exfiltrate data that is not yours.
  • Do not run denial-of-service tests, spam, or social-engineering attacks against our staff or customers.

Reporting other issues

Suspected misuse of the NoboFlow brand, phishing that impersonates NoboFlow, or account concerns can be reported to security@noboflow.com or through our Contact page.

Questions

Anything on this page you would like explained in more detail — for vendor reviews, procurement or due diligence — write to security@noboflow.com and we will respond.