Annual audit covering security, availability, confidentiality, and privacy.
Full compliance with the EU General Data Protection Regulation.
Compliance with the California Consumer Privacy Act.
Information security management system certification (in progress).
Eight pillars that protect your data, your workflows, and your business.
All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Encryption keys are rotated regularly and managed in a hardware-backed key management service.
Role-based access control with least-privilege defaults. SSO/SAML on Enterprise. Granular scopes for API keys. Multi-factor authentication for all team members.
SOC 2 Type II certified. GDPR and CCPA compliant. Data Processing Agreements (DPAs) available for Enterprise customers. Annual third-party penetration testing.
Hosted on cloud providers with rigorous physical and environmental controls. 99.99% uptime SLA. Automated failover across regions. Daily encrypted backups.
24/7 security monitoring with anomaly detection. Audit logs for all sensitive actions. Real-time alerting on suspicious activity. Quarterly access reviews.
Documented incident response runbooks. Mean time to detect under 15 minutes. Customer notifications within 24 hours of confirmed incidents. Post-incident reviews published.
Background checks for all employees. Annual security training. Access to production data is restricted to a small, audited group with a documented business need.
We never use your data to train AI models. Zero-retention modes available on Enterprise. Region-locked storage for data residency. Customer-controlled retention.
We take security reports seriously. If you believe you have discovered a vulnerability, please email us at security@flowmindlabs.ai with a detailed description and reproduction steps. We respond within 48 hours and acknowledge valid reports in our Hall of Fame. We ask that you give us reasonable time to remediate before public disclosure.