Security
Effective date: 2026-10-02
Last updated: 2026-10-02
1. Overview
We design Flowlange with security in mind. This page describes measures we implement; it is not a guarantee against all threats.
2. Implemented measures
Implemented controls include:
- Multi-tenant isolation with organization-scoped access
- Role-based access control (RBAC)
- Authenticated API access with JWT and workspace context
- Rate limiting on sensitive endpoints
- Upload validation and access-controlled file storage
- Webhook SSRF protections for outbound integrations
- Audit logging for authentication and billing events
- Encryption in transit (HTTPS/TLS)
3. Available features
Customers may use team permissions, API keys with scopes, and workspace controls to limit access within their organization.
4. Under development / not claimed
We do not currently claim SOC 2, ISO 27001, or HIPAA certification. Centralized error tracking (e.g. Sentry) is not documented as deployed. Formal penetration test reports are not published.
5. Reporting issues
Report security concerns to support@flowlange.com.
