Security
What HonorFlow actually does to keep an account reachable only by its owner.
Authentication
HonorFlow supports email and password sign-in, with passwords stored as a secure bcrypt hash — never plaintext. Phone and email one-time codes are also supported as additional sign-in methods. OTP codes expire after ten minutes and are hashed at rest.
Sessions
After a successful code, HonorFlow issues signed access and refresh tokens. API routes for your ledger require a valid session. Logging out revokes the refresh token.
What HonorFlow does not do
HonorFlow does not connect to your bank. It does not claim SOC 2, ISO, PCI, or end-to-end encryption certifications on this page because those are not published product claims.
Your controls
You can export your data or delete your account from Profile. Deletion revokes sessions and removes personal identifiers from the account.