Security & operations

Mynto asks for access to your company's bank account and books. That requires trust, and trust requires openness. Here is how the service is secured — and where you can verify it.

Sign-in with BankID

You sign in with Vipps or ID-porten — both built on BankID. Mynto never stores passwords; your identity is verified by Norwegian banking infrastructure, not by us.

Bank connectivity through licensed institutions

PSD2 access to your bank goes through Enable Banking Oy (licensed under the Finnish FSA) or Folio Bank AS (a Norwegian bank). You always authenticate directly with your own bank — Mynto never sees your banking credentials and cannot move money without your approval.

Data stored in the EU

Accounting and personal data is stored in the EU: database in Frankfurt, web application in Stockholm, backend in EU West. Every supplier that sees data is listed publicly in the sub-processor list, with location and transfer basis per supplier.

GDPR and data processing agreement

Every customer gets a data processing agreement with Eksire AS (org no 821 482 372). If you delete a company, the data is purged after a 90-day grace period — byte-complete, not merely flagged as deleted.

Norwegian bookkeeping-act requirements

Vouchers are stored with full traceability: every entry has a history of who or what posted it, and the books can be exported as SAF-T at any time — the format the Tax Administration uses in audits.

Operations in the open

System status is public at status.mynto.no. Errors are monitored around the clock, and changes to the service are published in the changelog.

Found a security issue?

Write to hjelp@mynto.no. We respond quickly and appreciate responsible disclosure.

Security & operations — Mynto