Security

Controls you can name, not just claims

This page describes the controls FinWallet operates. It is maintained by the FinWallet team and is not an independent certification.

Account access

Password rules, two-factor authentication, and an active session list you can revoke.

Withdrawal protection

Beneficiary verification, cooldown windows and a two-factor confirmation on every payout.

Immutable ledger

Balances are derived from append-only ledger entries. Records are never edited in place.

Risk review

Unusual patterns route to a reviewer who can hold a payout before it leaves the platform.

Audit logging

Every privileged staff action is written with actor, target, before and after state.

Data handling

Identity documents are stored for verification only and access is role-restricted.

We will never ask you for

Your password, your two-factor code, or remote access to your device. Support will never request them. Report anything that does to our security contact on the contact page.

FinWallet is not a licensed bank and holds no deposit-insurance guarantee. Shared responsibility applies: we operate the platform controls above, and you are responsible for protecting your credentials and device.