← Flowlange

Security

Effective date: 2026-10-02

Last updated: 2026-10-02

1. Overview

We design Flowlange with security in mind. This page describes measures we implement; it is not a guarantee against all threats.

2. Implemented measures

Implemented controls include:

  • Multi-tenant isolation with organization-scoped access
  • Role-based access control (RBAC)
  • Authenticated API access with JWT and workspace context
  • Rate limiting on sensitive endpoints
  • Upload validation and access-controlled file storage
  • Webhook SSRF protections for outbound integrations
  • Audit logging for authentication and billing events
  • Encryption in transit (HTTPS/TLS)

3. Available features

Customers may use team permissions, API keys with scopes, and workspace controls to limit access within their organization.

4. Under development / not claimed

We do not currently claim SOC 2, ISO 27001, or HIPAA certification. Centralized error tracking (e.g. Sentry) is not documented as deployed. Formal penetration test reports are not published.

5. Reporting issues

Report security concerns to support@flowlange.com.

This document is provided for information purposes only and does not constitute legal advice. Formal legal review is recommended before relying on it for compliance decisions.