Security

Security is
not optional

We protect your data and workflows with the same rigor we apply to our own. SOC 2 Type II certified, end-to-end encryption, and 24/7 monitoring.

SOC 2 Type II

Annual audit covering security, availability, confidentiality, and privacy.

GDPR

Full compliance with the EU General Data Protection Regulation.

CCPA

Compliance with the California Consumer Privacy Act.

ISO 27001

Information security management system certification (in progress).

Our security program

Eight pillars that protect your data, your workflows, and your business.

Encryption

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Encryption keys are rotated regularly and managed in a hardware-backed key management service.

Access Control

Role-based access control with least-privilege defaults. SSO/SAML on Enterprise. Granular scopes for API keys. Multi-factor authentication for all team members.

Compliance

SOC 2 Type II certified. GDPR and CCPA compliant. Data Processing Agreements (DPAs) available for Enterprise customers. Annual third-party penetration testing.

Infrastructure

Hosted on cloud providers with rigorous physical and environmental controls. 99.99% uptime SLA. Automated failover across regions. Daily encrypted backups.

Monitoring

24/7 security monitoring with anomaly detection. Audit logs for all sensitive actions. Real-time alerting on suspicious activity. Quarterly access reviews.

Incident Response

Documented incident response runbooks. Mean time to detect under 15 minutes. Customer notifications within 24 hours of confirmed incidents. Post-incident reviews published.

Personnel

Background checks for all employees. Annual security training. Access to production data is restricted to a small, audited group with a documented business need.

Data Privacy

We never use your data to train AI models. Zero-retention modes available on Enterprise. Region-locked storage for data residency. Customer-controlled retention.

Responsible disclosure

We take security reports seriously. If you believe you have discovered a vulnerability, please email us at security@flowmindlabs.ai with a detailed description and reproduction steps. We respond within 48 hours and acknowledge valid reports in our Hall of Fame. We ask that you give us reasonable time to remediate before public disclosure.