Compliance
Our approach to security, KYC/AML, data protection and regulatory obligations.
Last updated: June 2026
Flowsmin is built to help businesses move money safely and within the rules. We combine technical controls, verification processes and operational governance to meet the expectations of our banking and payment partners and applicable Indian regulations.
1. KYC & AML
Every vendor completes Know Your Customer (KYC) verification before activation. We maintain Anti-Money-Laundering (AML) controls including:
- identity and business verification with document review;
- risk-based onboarding and ongoing monitoring;
- transaction monitoring for suspicious activity;
- screening against applicable sanctions and watchlists.
2. Data & infrastructure security
- encryption of data in transit (TLS) and encryption of sensitive credentials at rest;
- role-based access control and least-privilege access to systems;
- audit logging of administrative and account activity;
- signed, verifiable webhooks and scoped API keys;
- infrastructure hosted in a secured Indian (BLR1) region with managed backups.
3. Card data & PCI-DSS
Card payments are handled through PCI-DSS aligned infrastructure and partners. We minimise the handling of raw card data and rely on tokenisation and partner-side processing wherever possible.
4. Data protection
Our handling of personal data is described in our Privacy Policy and is designed to align with India’s Digital Personal Data Protection (DPDP) Act, 2023, including principles of purpose limitation, data minimisation and retention control.
5. Compliance framework at a glance
| Area | Our approach |
|---|---|
| Identity (KYC) | Mandatory document-based verification before account activation |
| AML | Risk scoring, transaction monitoring and sanctions screening |
| Card security | PCI-DSS aligned processing; minimal raw card-data handling |
| Data protection | DPDP-aligned processing, encryption and retention controls |
| Auditability | Full transaction ledger and administrative activity logs |
6. Shared responsibilities
Compliance is a partnership. Vendors are responsible for the legality of their business, honouring valid refunds and disputes, safeguarding their credentials, and providing accurate information during onboarding and on request.
7. Reporting a concern
To report a security vulnerability, suspected fraud or a compliance concern, contact our team. We take every report seriously.