Trust & Safety

Security at Floo

Last reviewed: April 2026

Floo handles sensitive financial data. We treat security as a core product requirement, not an afterthought. This page explains exactly how we protect your data and our systems.

🔐
Encrypted in transit

All communication between your browser and Floo is encrypted using TLS 1.3. We enforce HTTPS on every endpoint.

🗄️
Encrypted at rest

Your data is encrypted at rest in our database. Passwords are hashed with bcrypt — even we cannot read them.

👁️
Read-only access

We connect to your Gmail in read-only mode via OAuth 2.0. We never store your Google password or credentials.

🛡️
Isolated customer data

Every customer's data is isolated. No customer can ever access another customer's transactions or alerts.

Infrastructure security

Application security

Gmail access — how it works

Floo connects to your Gmail account using Google's OAuth 2.0 protocol. This means:

Third-party security

Floo uses the following trusted third-party services, each with their own security certifications:

What we do NOT do

Reporting a security issue

If you discover a security vulnerability in Floo, please email us immediately at hello@tryfloo.com with the subject line "Security Vulnerability". We take all reports seriously and will investigate within 24 hours. We ask that you do not publicly disclose the issue until we have had the opportunity to address it.

We are grateful to security researchers who help us keep Floo safe and will acknowledge your contribution if you choose.

Security questions?

Our team is happy to answer detailed security questions from enterprise customers, auditors, or investors.

Email: hello@tryfloo.com

We respond within 1 business day for security enquiries.