Security
How Banking Central accesses your bank data, and where the data is kept.
Read-only access
Banking Central uses account information access under the European PSD2 rules: it reads transactions and balances. It cannot make payments or change anything at the bank.
Authorised at the bank
The access is authorised on the bank's own page, with the bank's strong customer authentication. Online banking credentials are never entered in Business Central and never reach Memento.
Regulated provider
Access to the banks goes through GoCardless Bank Account Data, a regulated account information service provider.
Access that expires
Each connection is valid for the period granted by the bank and can be revoked from Business Central at any time. Renewing it requires a new authorisation at the bank.
Transactions stay in your tenant
Transactions go directly from the provider to your Business Central environment and are stored there, under your Business Central permissions and retention policies. They never pass through Memento's servers.
What Memento receives
To manage the licence, Memento receives the tenant and environment identifiers, the company name and the billing details confirmed when the trial starts. Payments are processed by Stripe. Like every Business Central app, Banking Central sends standard technical telemetry to Memento, which contains no bank transactions.
Permissions and activity log
Three permission sets control who can view, use and configure Banking Central, and the activity log records the operations with the banks.
Sandbox copies
When production is copied to a sandbox, the bank connections are removed from the copy, so a test environment never imports with production access.
Questions from your IT or security team?
Write to [email protected].