Security & Trust

Your data stays yours

flowgen reads your website, public sources and the documents you choose to connect, and writes content your team approves. This page describes how that data is isolated, protected, retained and deleted. It is a summary of practice, not a certification claim.

SOC 2 readiness program in progress · no certification is claimed
SOC 2Readiness in progressflowgen is working through a SOC 2 readiness program. flowgen is not currently SOC 2 certified and does not represent otherwise.
ISO 27001Not certifiedNo ISO 27001 certification is held. Controls described below follow common practice and are documented on request.

How customer data is handled

Data privacy

flowgen processes the data needed to run your workspace: your website content, the documents you connect, the questions you track and the AI responses collected for them. Personal data handling is described in the privacy policy.

Customer data isolation

Each customer workspace is logically isolated. Verified facts, drafts, reports and connected sources belong to one workspace and are never shared across customers.

Encryption

Data is encrypted in transit using TLS and at rest using the storage provider’s encryption. Credentials for connected services are stored encrypted and are never shown back in full.

Access controls

Workspace members have roles, and publishing requires an approver role. Access by flowgen staff for support is limited, logged and granted only when a customer asks for help.

Data retention

Collected AI responses and reports are retained for the period set by your plan so that before-and-after comparisons remain possible. Retention periods can be shortened on request.

AI provider data handling

flowgen sends questions and, when drafting, the verified facts needed for a draft to the AI providers used in your workspace, under their API terms. Which providers are used is listed in the subprocessor list.

Model training policy

flowgen does not use customer workspace content to train models of its own. Provider terms governing API data are listed with each subprocessor.

Human approval workflows

Nothing is published to a connected channel without approval by a workspace member with the approver role. Automation prepares; people approve; flowgen executes.

Audit logs

Approvals, publications, fact changes and connection changes are logged with the user and time, and the log is available to workspace administrators.

Data deletion

Customers can delete connected sources, facts, drafts and whole workspaces. Deleted data is removed from active systems promptly and from backups on the backup rotation schedule.

Subprocessors

Hosting, storage, email and AI providers that process customer data are listed in the subprocessor list, available on request, with the purpose of each.

Vulnerability reporting

Security researchers can report issues through the vulnerability reporting page. Reports are acknowledged and tracked to resolution.

Need the detailed documentation?

Security questionnaires, the subprocessor list and data processing terms are available on request.