StewardFlow

StewardFlow

Security & privacy

Back to site

Security & privacy

Technical controls, privacy practices, and compliance information for procurement and IT review.

Security

Our role vs. your bank

Rekhoni provides designated-fund bookkeeping software — not banking services. By default, inter-fund entries update your ledger only; they do not move money at your financial institution unless you explicitly enable a bank-instruction or payment-rail mode. Your organization retains ownership of all bank relationships.

Encryption & infrastructure

Data is encrypted in transit using TLS 1.2+. Credentials are hashed; session cookies are HTTP-only. Production environments use hardened infrastructure, least-privilege access, and regular patching.

Access controls

Application access requires authenticated login with role-based permissions. Sensitive actions — large transfers, disbursements, user management — can require dual control with submitter and approver both recorded.

Audit logging

Allocations, transfers, approvals, exports, and sign-in events are timestamped with user attribution. Logs support board review, annual audit, and internal investigation.

Bank connectivity

Bank linking uses Plaid's encrypted, read-only connections. We do not store online banking usernames or passwords.

Incident response

Report security concerns to security@rekhoni.com. We investigate validated reports promptly and notify affected organizations of confirmed breaches as required by applicable law and contract.

Responsible disclosure

If you believe you have found a vulnerability, contact security@rekhoni.com with enough detail to reproduce the issue. Do not attempt to access data that is not yours.

Privacy policy

Scope

This policy describes how Rekhoni collects, uses, and protects information when you use our designated-fund bookkeeping software and related services. It applies to administrators, finance users, and other authorized users at your organization.

Information we collect

We collect account and profile information (name, email, role), organization configuration (funds, rules, chart mappings), financial transaction data you enter or import, bank balance metadata via Plaid (not banking credentials), usage and audit logs, and support correspondence.

How we use information

We use data to provide and improve the service, authenticate users, enforce access controls, generate reports and forecasts, respond to support requests, meet legal obligations, and maintain security. We do not sell personal information or use customer financial data for advertising.

Sharing & subprocessors

We share data only as needed to operate the service: infrastructure hosting, email delivery, Plaid for bank connectivity, and other subprocessors under contract with appropriate security terms. A current subprocessor list is available on request at privacy@rekhoni.com.

Retention & deletion

We retain data for the life of your subscription and for a reasonable period afterward to meet legal, audit, and backup requirements. Organizations may request export or deletion subject to contractual terms and applicable law.

Your rights

Depending on jurisdiction, you may have rights to access, correct, delete, or restrict processing of personal information. Contact privacy@rekhoni.com for requests. We will verify the requester is authorized to act on behalf of your organization.

Updates

We may update this policy as the product or law changes. Material changes will be communicated to account administrators. The effective date of the current version is shown at the bottom of this page.

Compliance & certifications

SOC 2

Rekhoni is built with SOC 2–aligned controls: access management, audit logging, change management, and separation of duties. Formal SOC 2 Type II certification is on our enterprise roadmap; contact us for the latest status and security questionnaire responses.

Financial stewardship

The product supports segregation of duties, immutable audit trails, and designated-fund accounting workflows common in churches, nonprofits, agencies, and regulated industries. Rekhoni complements — does not replace — your accountant's system of record.

Healthcare (CareFlow)

When CareFlow stores client or caregiver information, treat it as sensitive operational data. HIPAA-aware access controls and audit trails are available; organizations requiring HIPAA coverage should execute a Business Associate Agreement before production use with PHI.

Data processing agreement

Enterprise customers receive a Data Processing Addendum (DPA) covering processor obligations, subprocessors, breach notification, and data subject requests. Contact hello@rekhoni.com to request standard contract terms.

Deployment options

Enterprise customers can deploy on-premises or self-hosted on their infrastructure. On-premises is a common fit when financial data must stay inside your network. Scope depends on security review, integration requirements (Plaid, email, accounting OAuth), and support SLA. Contact us for deployment architecture and pricing.

This page summarizes our practices in plain language and is not a legal contract. Specific commitments are defined in your Master Services Agreement, Data Processing Addendum, and executed order forms. Effective August 2026.

Contact: Security security@rekhoni.com · Privacy privacy@rekhoni.com · General hello@rekhoni.com