Funded with Flow Legal Center
Home / Legal Center / Security
Security

Security

How we protect accounts and payments, how you can protect yourself, and how to report a vulnerability.

Effective: June 18, 2026 Last updated: June 18, 2026 Version: 1.0 Reading time: ~3 min
On this page
  • Our Approach to Security
  • Account Protection and Your Responsibility
  • Encrypted Connections and Session Security
  • API and MCP Key Safety
  • Secure Payment Handling
  • Monitoring and Audit Logging
  • Administrative Access Controls
  • Reporting a Security Concern
  • User Security Best Practices
  • Shared Responsibility
On this page
  • Our Approach to Security
  • Account Protection and Your Responsibility
  • Encrypted Connections and Session Security
  • API and MCP Key Safety
  • Secure Payment Handling
  • Monitoring and Audit Logging
  • Administrative Access Controls
  • Reporting a Security Concern
  • User Security Best Practices
  • Shared Responsibility

1. Our Approach to Security

Funded with Flow L.L.C. (Funded with Flow, the Platform, we, us) takes the security of our platform and our users seriously. This Security Statement describes security controls we have in place and the steps you can take to help protect your account.

This statement describes our practices in good faith and reflects only controls we can confirm. It is not a warranty or guarantee of security, and no method of transmission or storage is perfectly secure.

2. Account Protection and Your Responsibility

Protecting your account is a shared effort, and your actions matter. We recommend that you:

  • Use a strong, unique password that you do not reuse on other services;
  • Keep your credentials confidential and never share them;
  • Sign out when using shared or public devices; and
  • Promptly report any suspected unauthorized access.

You are responsible for maintaining the confidentiality of your credentials and for activity that occurs under your account.

3. Encrypted Connections and Session Security

Traffic to and from the Platform is protected in transit using TLS/HTTPS, delivered through our content-delivery and edge provider. This helps protect data as it travels between your device and the Platform.

Authenticated access uses session cookies. We apply protections appropriate to session-cookie authentication to help guard your signed-in session.

4. API and MCP Key Safety

API and MCP keys are handled with safeguards designed to limit risk:

  • Keys are stored as cryptographic hashes (HMAC), never in plaintext, and are shown only once at creation;
  • Keys are scoped to your own account, with read-only access by default and trade-execution permission gated behind opt-in controls;
  • Keys are revocable and rate-limited.

You are responsible for keeping your keys secret, rotating them periodically, and revoking any key that may have been exposed. See our API Terms and AI, MCP & Automation Terms for details.

5. Secure Payment Handling

Card payments are processed by Stripe, our payment processor. Stripe handles cardholder data, and PCI compliance for card processing is Stripe's responsibility. The Platform does not store full payment card numbers. Please review Stripe's practices for details on how card data is handled.

6. Monitoring and Audit Logging

We log and monitor activity across the Platform, including authentication events and API/MCP access, to help detect, investigate, and respond to security incidents and misuse. Logs are retained for safety, debugging, security, and compliance purposes.

7. Administrative Access Controls

Administrative access to the Platform is role-restricted and limited to authorized personnel based on their role. Administrative actions are subject to audit logging to support accountability and incident investigation.

8. Reporting a Security Concern

If you discover a potential vulnerability or security issue, please report it responsibly to [email protected].

When reporting, please include enough detail for us to reproduce and assess the issue, and avoid accessing, modifying, or destroying data that does not belong to you. We appreciate good-faith reports and will review them promptly.

9. User Security Best Practices

To help keep your account secure, we recommend that you:

  • Use a strong, unique password and a reputable password manager;
  • Keep your devices, browsers, and operating systems up to date;
  • Be alert to phishing and never enter your credentials on untrusted sites;
  • Sign out on shared or public devices;
  • Grant API/MCP scopes only as needed and revoke unused keys; and
  • Test automation in paper mode before enabling any trade-execution permission.

10. Shared Responsibility

Security is a shared responsibility between Funded with Flow and you. We work to protect the Platform, and you play an essential role by safeguarding your credentials and keys. No system, method of transmission, or method of storage is perfectly secure, and we cannot guarantee absolute security.

We may update this document from time to time. When we make material changes we will update the “Last updated” date above and, where appropriate, ask you to review or re-accept it. Your continued use of the platform after an update means you accept the current version where permitted by law. See the Version History.
Back to Legal Center
Funded with Flow

Funded with Flow provides simulated evaluation and funded trading accounts for practice and education. It is not a broker-dealer, investment adviser, exchange, custodian, or bank, and provides no financial advice. Trading involves substantial risk of loss.

Legal CenterTerms of ServicePrivacy PolicyCookie PolicyRisk DisclosureTrading RulesRefund PolicyLegal & Company Contact
© 2026 Funded with Flow L.L.C. All rights reserved. · fundedwithflow.com