Security

How Banking Central accesses your bank data, and where the data is kept.

  • Read-only access

    Banking Central uses account information access under the European PSD2 rules: it reads transactions and balances. It cannot make payments or change anything at the bank.

  • Authorised at the bank

    The access is authorised on the bank's own page, with the bank's strong customer authentication. Online banking credentials are never entered in Business Central and never reach Memento.

  • Regulated provider

    Access to the banks goes through GoCardless Bank Account Data, a regulated account information service provider.

  • Access that expires

    Each connection is valid for the period granted by the bank and can be revoked from Business Central at any time. Renewing it requires a new authorisation at the bank.

  • Transactions stay in your tenant

    Transactions go directly from the provider to your Business Central environment and are stored there, under your Business Central permissions and retention policies. They never pass through Memento's servers.

  • What Memento receives

    To manage the licence, Memento receives the tenant and environment identifiers, the company name and the billing details confirmed when the trial starts. Payments are processed by Stripe. Like every Business Central app, Banking Central sends standard technical telemetry to Memento, which contains no bank transactions.

  • Permissions and activity log

    Three permission sets control who can view, use and configure Banking Central, and the activity log records the operations with the banks.

  • Sandbox copies

    When production is copied to a sandbox, the bank connections are removed from the copy, so a test environment never imports with production access.

Questions from your IT or security team?

Write to [email protected].