Security
Controls you can name, not just claims
This page describes the controls FinWallet operates. It is maintained by the FinWallet team and is not an independent certification.
Account access
Password rules, two-factor authentication, and an active session list you can revoke.
Withdrawal protection
Beneficiary verification, cooldown windows and a two-factor confirmation on every payout.
Immutable ledger
Balances are derived from append-only ledger entries. Records are never edited in place.
Risk review
Unusual patterns route to a reviewer who can hold a payout before it leaves the platform.
Audit logging
Every privileged staff action is written with actor, target, before and after state.
Data handling
Identity documents are stored for verification only and access is role-restricted.
We will never ask you for
Your password, your two-factor code, or remote access to your device. Support will never request them. Report anything that does to our security contact on the contact page.
FinWallet is not a licensed bank and holds no deposit-insurance guarantee. Shared responsibility applies: we operate the platform controls above, and you are responsible for protecting your credentials and device.