How We Protect Your Data
A summary of the practices behind the platform. Detailed policies and reports are available through the document request flow below.
Encryption
All data is encrypted in transit with TLS 1.2/1.3 and at rest with AES-256 using FIPS 140-2 validated cryptographic modules. Backups are encrypted the same way as production data.
Data Residency
Customer data is stored in ISO 27001-certified datacenters located in Brazil.
Access Control
Single Sign-On (SAML 2.0 / OIDC), enforced MFA for internal staff, role-based access control with granular access groups, and least-privilege access with periodic reviews.
Secure Development
Every change is peer reviewed and runs through an automated pipeline with static analysis, dependency and image scanning, following OWASP secure-coding practices. Production changes are restricted and require approval.
Network Protection
Web application firewall, DDoS protection, and zero-trust access to internal systems, with continuous monitoring for errors and anomalous behavior.
Resilience
Daily automated encrypted backups with regularly tested restores, plus a documented Disaster Recovery Plan tested at least annually.
Assessments and Commitments
Penetration Testing
Flowls undergoes annual penetration testing by an independent third-party security firm.
The full report is available under the document request flow.
Incident Notification
In the event of a confirmed security incident affecting customer data, Flowls commits to notifying affected customers within 3 days of confirmation, following our Incident Response Plan.
Vulnerability Remediation SLAs
Vulnerabilities are triaged by severity and remediated within defined targets. No software is deployed to production with unresolved urgent or high vulnerabilities unless an approved exception is in place.
| Severity | Remediation target |
|---|---|
| Urgent | 24 hours |
| High | 7 days |
| Normal | 30 days |
| Low | Best effort |
Security Controls
App Security
Infrastructure Security
Organization Security
Policies and Documents
Our full security policies and reports are available on request. Select a document to start a request. We typically respond within one business day.
Policies
Information Security Policy
Our overarching security program: governance, roles, and baseline controls.
Request →Incident Response Plan
How we detect, contain, and communicate security incidents.
Request →Disaster Recovery Plan
Recovery phases, responsibilities, and testing for major disruptions.
Request →Backup Policy
Backup cadence, encryption, monitoring, and restore testing.
Request →Vulnerability Management Policy
Scanning, triage, and severity-based remediation SLAs.
Request →Software Development Lifecycle Policy (SDLC)
Secure development practices, code review, and change control.
Request →Password Policy
Password and credential requirements for systems and staff.
Request →Data Protection Policy
Controls protecting customer data across its lifecycle.
Request →Data Retention Policy
How long data is kept and how it is securely disposed.
Request →Data Classification Policy
How information is classified and handled by sensitivity.
Request →Artificial Intelligence Usage Policy
Rules for the responsible use of AI tools and systems.
Request →Code of Conduct
Ethical and professional standards for everyone at Flowls.
Request →Frequently Asked Questions
Where is my data stored?
Customer data is stored in ISO 27001-certified datacenters located in Brazil.
Is my data encrypted?
Yes. Data in transit is encrypted with TLS 1.2/1.3, and data at rest with AES-256 using FIPS 140-2 validated cryptographic modules. Backups are encrypted the same way as production data.
How is my data isolated from other customers?
Flowls is a multi-tenant platform with strict logical isolation. Every client authenticates against an account and receives an access token scoped to that account, authorization is enforced at the API layer, and all database queries are scoped by the account identifier.
Do you support Single Sign-On?
Yes. We support SSO via SAML 2.0 and OIDC, including native Azure AD / Entra ID integration, so you can manage users through your own identity provider.
What happens to our data when the contract ends?
When an account is closed, its data enters an expired state and is permanently deleted after a 30-day grace period, unless retention is legally required.
Will we be notified about security incidents?
Yes. Confirmed incidents affecting customer data are communicated to affected customers within 3 days of confirmation, as defined in our Incident Response Plan.
Is production data used in test environments?
No. Production is the only environment with real customer data, with access limited to necessary personnel. Non-production environments use synthetic or anonymized data.
Security Contact & Responsible Disclosure
Questions about our security practices, or something to report? Reach our security team at [email protected].
If you believe you have found a security vulnerability in a Flowls product or service, please report it to the address above with enough detail for us to reproduce the issue. We will acknowledge your report, investigate promptly, and keep you informed of the resolution. We ask that you act in good faith, avoid accessing or modifying data that is not yours, and give us reasonable time to remediate before any public disclosure. We will not pursue legal action against good-faith security research conducted under these guidelines.