Security at Flowls

Security is built into how we design, develop, and operate the Flowls platform. Explore our practices, controls, and commitments.

How We Protect Your Data

A summary of the practices behind the platform. Detailed policies and reports are available through the document request flow below.

Encryption

All data is encrypted in transit with TLS 1.2/1.3 and at rest with AES-256 using FIPS 140-2 validated cryptographic modules. Backups are encrypted the same way as production data.

Data Residency

Customer data is stored in ISO 27001-certified datacenters located in Brazil.

Access Control

Single Sign-On (SAML 2.0 / OIDC), enforced MFA for internal staff, role-based access control with granular access groups, and least-privilege access with periodic reviews.

Secure Development

Every change is peer reviewed and runs through an automated pipeline with static analysis, dependency and image scanning, following OWASP secure-coding practices. Production changes are restricted and require approval.

Network Protection

Web application firewall, DDoS protection, and zero-trust access to internal systems, with continuous monitoring for errors and anomalous behavior.

Resilience

Daily automated encrypted backups with regularly tested restores, plus a documented Disaster Recovery Plan tested at least annually.

Assessments and Commitments

Penetration Testing

Flowls undergoes annual penetration testing by an independent third-party security firm.

The full report is available under the document request flow.

Incident Notification

In the event of a confirmed security incident affecting customer data, Flowls commits to notifying affected customers within 3 days of confirmation, following our Incident Response Plan.

Vulnerability Remediation SLAs

Vulnerabilities are triaged by severity and remediated within defined targets. No software is deployed to production with unresolved urgent or high vulnerabilities unless an approved exception is in place.

SeverityRemediation target
Urgent24 hours
High7 days
Normal30 days
LowBest effort

Security Controls

App Security

Software Development Lifecycle
Automated tests and quality checks enforced
Recurring Penetration Tests
Vulnerability scanning on every code change
Tenant Data Isolation
Single Sign-On (SAML 2.0 / OIDC)

Infrastructure Security

Software Versions Updated
Backup Policy
Password Policy
Data encrypted at rest and in transit
WAF and DDoS protection
Security monitoring and logging
Production data segregated from test environments

Organization Security

Code Review Process
Annual Access Reviews
MFA enforced for all staff
Least-privilege access control
Disaster Recovery Plan
Incident Response Plan
Data retention and secure disposal
Third-party vendors security-certified
Production Code Changes Restricted
Security Issues are Prioritized

Policies and Documents

Our full security policies and reports are available on request. Select a document to start a request. We typically respond within one business day.

Frequently Asked Questions

Where is my data stored?

Customer data is stored in ISO 27001-certified datacenters located in Brazil.

Is my data encrypted?

Yes. Data in transit is encrypted with TLS 1.2/1.3, and data at rest with AES-256 using FIPS 140-2 validated cryptographic modules. Backups are encrypted the same way as production data.

How is my data isolated from other customers?

Flowls is a multi-tenant platform with strict logical isolation. Every client authenticates against an account and receives an access token scoped to that account, authorization is enforced at the API layer, and all database queries are scoped by the account identifier.

Do you support Single Sign-On?

Yes. We support SSO via SAML 2.0 and OIDC, including native Azure AD / Entra ID integration, so you can manage users through your own identity provider.

What happens to our data when the contract ends?

When an account is closed, its data enters an expired state and is permanently deleted after a 30-day grace period, unless retention is legally required.

Will we be notified about security incidents?

Yes. Confirmed incidents affecting customer data are communicated to affected customers within 3 days of confirmation, as defined in our Incident Response Plan.

Is production data used in test environments?

No. Production is the only environment with real customer data, with access limited to necessary personnel. Non-production environments use synthetic or anonymized data.

Security Contact & Responsible Disclosure

Questions about our security practices, or something to report? Reach our security team at [email protected].

If you believe you have found a security vulnerability in a Flowls product or service, please report it to the address above with enough detail for us to reproduce the issue. We will acknowledge your report, investigate promptly, and keep you informed of the resolution. We ask that you act in good faith, avoid accessing or modifying data that is not yours, and give us reasonable time to remediate before any public disclosure. We will not pursue legal action against good-faith security research conducted under these guidelines.