Secure by design, not by setting.
Privacy, audit and EU hosting are built into FlowSentric from the ground up. This page says exactly what we do — and what we don't claim.
Security foundations
Encryption
TLS in transit at the edge. Application secrets, integration tokens, SSO client secrets and MFA seeds are encrypted at rest with authenticated encryption and rotating keys; passwords are stored only as hashes.
Tenant isolation
Authorization is enforced on every read and write. A user only ever sees their own data or the organizations they belong to; cross-tenant access is blocked and covered by tests.
Audit logging
Security-relevant actions are recorded with actor and timestamp, retained per plan (14 to 365 days), and exportable as CSV — for yourself, or organization-wide as an owner.
Guarded integrations
Every outbound tool, database, webhook and integration call passes a network safety guard that blocks private and internal networks, pins resolved addresses and re-validates on every redirect.
EU hosting & EU models
Application and database are hosted in the EU. For AI requests, 26 models are routed through an EU gateway and labelled “(EU)”; local models never leave the box. Transfers to US providers rely on SCCs or an adequacy decision.
Never used to train
Your prompts, documents and outputs are never sold and never used to train models — ours or anyone else's. Long-term memory is opt-in and fully deletable.
What Privacy Guard masks before it reaches a model
Detection runs in several layers — pattern rules, industry-standard recognisers and language-aware name recognition in English and German, with an optional local model pass. Masking is reversible per request — the real values are restored in the answer only in your view — and the Privacy Log stores the type and count of masked items, never the values. Agents have Privacy Guard on by default; organization admins can lock it on for restricted accounts. Models routed through the EU gateway are labelled “(EU)”, e.g. “Claude Opus 4.6 (EU)”.
Identity and access
Sign-in
- Password policy: 8+ characters with upper, lower, number and special character
- Two-factor authentication with authenticator apps and hashed backup codes
- Google and GitHub social login; email verification
- httpOnly, SameSite session cookies
Enterprise SSO
- OpenID Connect with automatic discovery and signed-key verification
- SAML 2.0
- SCIM 2.0 user provisioning and de-provisioning
- DNS-verified domains and enforced SSO per organization
Authorization
- Organization roles: admin, editor, member, viewer
- Restricted accounts with allowed agents, models and features
- API keys with read / write / execute scopes, optionally pinned to agents
- Rate limiting per user, IP address and endpoint
Your data, your controls
Export
- Full account export as JSON (GDPR Art. 20)
- Activity and organization audit export as CSV
- Conversations as Markdown, HTML or PDF
Retention
- Chat history and logs follow your plan's retention (7 days to unlimited)
- AI Sessions are temporary and expire automatically
- Meeting audio is deleted once transcribed; only transcript and notes persist
Deletion
- Self-service account deletion with password confirmation
- Name and email are anonymized immediately; sessions and API keys are revoked
- Full content purge on request within 30 days
Where processing happens
EU infrastructure
- Application, database and file storage on EU-based hosting
- Video meetings on our own self-hosted infrastructure
- Cookieless, self-hosted analytics on this website
Local by default
- Knowledge-base embeddings computed on our own servers
- Audio and meeting transcription on our own servers
- Optional local vision model for OCR; local models for chat and PII detection
Operations
- Regular database backups with a documented restore procedure
- Breach notification to affected business customers without undue delay, as a rule within 48 hours
- Responsible disclosure: report vulnerabilities to hello[at]flowsentric.com
Compliance documentation
We do not hold an ISO 27001 or SOC 2 certification today, and we do not promise that data “never leaves the EU” — you choose the model, and we label where it runs. If a claim is not on this page, do not assume it.