Security
Payment data deserves careful handling.
EzeFlow holds invoices, supplier bank details and approval records. This page explains, plainly, how we protect them and what you control.
Sign-in
- Passwords are stored as one-way hashes, never in readable form
- Two-factor sign-in with an emailed code or a free authenticator app (Google or Microsoft Authenticator)
- Recovery codes in case a phone is lost
- Administrators can make two-factor sign-in compulsory for finance and admin roles
- Accounts lock temporarily after repeated failed sign-ins
- Sessions end after a period of inactivity that you choose (15 minutes to 8 hours)
Who sees what
- Each company has its own account and web address
- Users only see the organizations they are assigned to, in lists, reports, search, exports and the audit log
- Built-in roles and custom roles from 24 permissions
- Only a named bank team can change supplier bank details or download payment files
- Documents are only available to people who may see the payment
Payments and bank details
- Supplier bank account numbers are stored encrypted with a 256-bit key and shown masked
- Every change to supplier bank details is recorded
- Batches warn when bank details changed after a payment was approved
- EzeFlow never moves money: FNB authorisers release payments in FNB
Records and audit
- Audit log of sign-ins, approvals, rejections, edits, payments and exports, searchable and exportable to CSV
- Each uploaded document gets a digital fingerprint (SHA-256) so duplicates are recognised
- Your data can be exported to CSV at any time
Infrastructure
- Hosted in Johannesburg, South Africa (Xneelo)
- All traffic over HTTPS, with HSTS
- Protection against cross-site request forgery and rate limits on sign-in and forms
- Public website indexed by search engines; your company's pages never are
Found a security problem?
Please tell us before telling anyone else, and give us a reasonable time to fix it. Email support@ezeflow.co.za with "Security" in the subject.
For POPIA requests (a copy of your personal information, corrections or deletion) use the same address.
Where is EzeFlow hosted?
On servers in Johannesburg, South Africa, run by Xneelo. Your payment data stays in the country.
Is our data kept apart from other companies?
Yes. Every company has its own account and web address, and every record is tied to its company. Within your account, users only see the organizations they are assigned to.
Is two-factor sign-in compulsory?
Each user can switch it on, and an administrator can make it compulsory for the finance and admin roles. Users choose between an emailed code and a free authenticator app.
Are supplier bank details encrypted?
Yes. Supplier bank account numbers in the bank payments module are stored encrypted with a 256-bit key and shown masked. Only the bank team can change them, and every change is recorded.
Can EzeFlow move money from our bank account?
No. EzeFlow has no access to your bank. It creates a payment file that your team imports into FNB, where your own authorisers release the payments.
How do we ask for our personal information, or have it deleted?
Email support@ezeflow.co.za. We respond to access and deletion requests under POPIA.
See it with your own payments.
Start a 7-day free trial without a card, or look around a demo company with sample data first.