Skip to content
FLOWTYPE

SECURITY

Designed for enterprise control.

Automation touches sensitive systems, so control is part of the design: who can build, who can approve, what is recorded and how secrets are handled.

This page describes FLOWTYPE’s planned security architecture and design principles. FLOWTYPE has not claimed any third-party certification or attestation.

Explore

Security controls, one at a time.

Designed for enterprise control

Design intent · illustrative

Authentication

Designed to support email and password, Google and Microsoft sign-in, and enterprise single sign-on (SAML/OIDC) as an enterprise control.

  • Email and passwordPlanned
  • Google sign-inPlanned
  • Microsoft sign-inPlanned
  • Enterprise SSO (SAML / OIDC)Enterprise control

No security certifications or attestations are claimed. This describes planned architecture.

Overview

Ten areas of the security design.

  • Security overview

    Designed around least privilege, isolation between workspaces and auditability.

  • Authentication

    Email sign-in, Google and Microsoft options, and enterprise SSO are planned.

    Planned

  • Authorization

    Permissions checked at workspace and workflow level.

    Designed

  • Encryption

    Designed to protect data in transit and at rest.

    Designed

  • Credential protection

    Secrets stored separately, masked after entry and kept out of logs.

    Designed

  • Audit logs

    A planned record of who changed and ran what, and when.

    Planned

  • Access control

    Roles for owners, admins, builders, approvers and viewers.

    Designed

  • Monitoring

    Operational monitoring and alerting for platform health.

    Planned

  • Data handling

    Retention and location controls will be documented before general availability.

    Planned

  • Enterprise controls

    Enterprise controls can include SSO, granular permissions and extended audit retention.

    Enterprise

Compliance status

No certifications are claimed.

FLOWTYPE has not completed any compliance programme or third-party audit. We do not display certification badges.

If and when a certification or attestation is achieved, it will be announced on this page with its scope and date. Until then, treat this page as a description of design intent.

Have security requirements for a specific evaluation? Contact sales and tell us what you need to see.

TALK TO US ABOUT SECURITY.

Tell us about your identity, data handling and audit requirements.