Cash Flow Frog logo

Trust Center

Certified and annually reviewed by independent third-party auditors. Our certifications are issued and reviewed annually by independent third parties.

ISO 27001 CertifiedISO 27001 Certified

ISO 27001 is the international standard for information security management. Achieving certification means our systems, processes, and people have been independently audited against a rigorous global benchmark — not just a checklist we filled out ourselves. It covers everything from how we store your data to how we respond to incidents, and it requires us to re-certify every year.

GDPR CompliantGDPR Compliant

We comply with the EU General Data Protection Regulation. That means we collect only what’s necessary, we tell you what we do with it, and you can access, correct, or delete your data at any time. We also maintain a signed Data Processing Agreement (DPA) for any business that needs one for their own compliance obligations.

Security built into every layer

Your data is protected at every level, from the moment you connect.

🔐 Encryption everywhere
All data is encrypted in transit and at rest.
Continuous monitoring

Our systems are monitored 24/7 for anomalies. Security events are alerted on automatically with defined escalation procedures.

Strict access controls

Only authorised Cash Flow Frog personnel can access production systems, and only when it’s needed. All access is logged and reviewed.

Two-factor authentication

Add extra protection to your account. Cash Flow Frog supports authenticator apps and SMS codes. Enable it in settings — see the 2FA guide below.

Regular penetration testing

We conduct independent penetration tests on a recurring basis to identify and fix vulnerabilities before they can be exploited.

Incident response

We maintain a documented incident response plan. If a breach ever occurred, we’re required to notify affected users within 72 hours.

Secure cloud infrastructure

Our servers are hosted on enterprise-grade cloud infrastructure with redundancy, backups, and physical security controls.

Ready to take control of your cash flow?

Learn more & sign up here

Sign up Now
Cta image
You own your data — always

We will never sell your data or share it with third parties for marketing. Here’s exactly what you can expect.

Access your data anytime

Export your forecasts, scenarios, and account data at any time from your account settings.

Request deletion

Close your account and we’ll permanently delete your data. No dark patterns, no waiting period.

We never sell your data

Your financial data is used only to power your forecasts. It is never sold or shared with advertisers.

Read-only accounting access

When you connect QuickBooks, Xero, or Sage, we request read-only access — we can never write or change your books.

Documentation

Everything in one place

🛡️ ISO 27001 Certificate

Current certificate issued by accredited body

Download PDF
📄 Data Processing Agreement (DPA)

Current certificate issued by accredited body

Download DPA
🔒 Privacy Policy

Current certificate issued by accredited body

View Policy
📋 Subprocessors List

Current certificate issued by accredited body

View List
📑 Terms of Service

Current certificate issued by accredited body

View Terms
📱 How to enable 2FA

Current certificate issued by accredited body

View Guide

Have a security question?

Our team responds to security enquiries within one business day.

Start free forecast14-day free trial • No credit card required
Review
ISO 27001 Certified
GDPR Compliant
256-bit Encryption
2FA Available
Read-only Accounting Access