TRUST & SECURITY

Security you can hand to your compliance team.

FlowSmartly protects customer data with encryption, least-privilege access, continuous monitoring, and independent audits.
In the security overview
Architecture, data flow, and where each system runs
The control matrix, mapped framework by framework
Our subprocessor list and the residency options
A completed security questionnaire your reviewers can lift from
COMPLIANCE

The frameworks we are held to.

Independently assessed, contractually backed, and re-tested every year — not a self-declaration.
SOC 2 Type II
Audited annually
GDPR
DPA and SCCs
CCPA
Opt-out honored
ISO 27001
ISMS certified
HIPAA-ready
BAA available
HOW WE PROTECT YOUR DATA

Six controls that run whether or not anyone is watching.

They are engineering defaults rather than policies in a binder — every one of them is enforced in the platform itself.
Encryption in transit and at rest
TLS 1.2 or better on every connection, AES-256 for stored data, and the same treatment for every backup and export.
Least-privilege access
Staff access is granted by role, scoped to the task, reviewed every quarter, and removed automatically when someone changes team.
Continuous monitoring
Infrastructure, application and audit events stream into a detection pipeline that pages an on-call engineer around the clock.
Secure development lifecycle
Peer review, dependency scanning, secret detection and automated security tests gate every change before it can deploy.
Vendor due diligence
Every subprocessor is security-reviewed before it touches customer data, bound by contract, and re-reviewed each year.
Business continuity
Encrypted backups, multi-zone failover and a documented recovery plan that we rehearse twice a year against real targets.
YOUR CONTROLS

What you can enforce yourself.

Security is not something we do to your workspace on your behalf. These are switches your admins own.
Role-based permissions
Give each teammate exactly the access their job needs — down to a single channel, campaign or store.
SSO & SAML
Bring your own identity provider, enforce your MFA and password rules, and de-provision people in one place.
Audit logs
Every sign-in, permission change, export and send is recorded with who did it, what changed and when.
Data export
Take contacts, content and reporting out on demand, in open formats, without asking anyone for permission.
Data deletion
Delete a contact, a workspace or everything, with a documented deletion window and written confirmation when it is done.
INDEPENDENT TESTING

We do not grade our own homework.

Outside researchers and accredited auditors test the same platform your team uses, on a published cadence.
Penetration testing
An independent firm tests the platform, the API and the infrastructure every six months, and again before any major architectural change. Summary reports are available under NDA.
Twice a year
Bug bounty
A researcher programme with published scope, defined reward tiers and safe-harbour terms, so good-faith testing is welcome rather than risky.
Always open
Third-party audits
SOC 2 Type II and ISO 27001 assessments are carried out each year by accredited external auditors, covering security, availability and confidentiality.
Annual
INCIDENT RESPONSE

What happens in the first hour, and the first week.

One rehearsed runbook, the same every time, with a written commitment on when you hear from us.
Detect
Automated alerting and 24/7 on-call put a named responder on the incident within minutes of the first signal.
Contain
An incident commander isolates the affected systems, rotates credentials and stops the blast radius from growing.
Notify
Affected customers hear from us without undue delay, and supervisory authorities within 72 hours where the law requires it.
Learn
A blameless post-mortem, a written summary for customers, and tracked fixes with an owner and a date on each one.
The 72-hour notification commitment
If a personal data breach affects your workspace, we notify you without undue delay and, where the law requires it, the relevant supervisory authority within 72 hours of becoming aware — with what happened, what data was involved, and what we have already done about it.
SUBPROCESSORS AND DATA RESIDENCY

Where your data lives, and who else can see it.

A short, published list of subprocessors, and a region you choose rather than one you inherit.
Subprocessors
We use a deliberately small number of subprocessors for infrastructure, delivery and support. Each one is security-reviewed before it is engaged, bound to process data only on our documented instructions, and listed publicly with what it does and where it operates.
Customers on a data processing agreement are notified before a new subprocessor is added, with time to object.
Data residency
Choose the region your workspace data is stored and processed in. Transfers outside it rely on approved mechanisms such as Standard Contractual Clauses, with the additional safeguards those clauses require.
United States
Primary region, with multi-zone replication
European Union
Frankfurt, for customers who elect EU residency
United Kingdom
London, available on request
Australia
Sydney, available on request

Report a vulnerability

Found something? Tell us before you tell anyone else, and we will treat it as the favour it is. Reports go straight to the security team, not to a shared inbox.
Dedicated address
security@flowsmartly.com
PGP key
flowsmartly.com/.well-known/security.txt
Coordinated disclosure, in four lines
Write to security@flowsmartly.com with the steps to reproduce and any proof-of-concept you have.
We acknowledge every report within one business day and give you a triage decision within five.
Good-faith research is covered by safe harbour — we will not pursue legal action for it.
Please hold public disclosure for 90 days, and never access, modify or keep data that is not yours.

Ready to move AI beyond assistance?

One intelligent system across your work, customers, content, tools and decisions — with FlowAgent executing inside the authority you define.
No credit card • Governed authority • Leave the list anytime
© 2026 FlowSmartly. All rights reserved.
Privacy
Terms
Cookies
GDPR
SMS Terms