SECURITY
Designed for enterprise control.
Automation touches sensitive systems, so control is part of the design: who can build, who can approve, what is recorded and how secrets are handled.
This page describes FLOWTYPE’s planned security architecture and design principles. FLOWTYPE has not claimed any third-party certification or attestation.
Explore
Security controls, one at a time.
Designed for enterprise control
Design intent · illustrativeAuthentication
Designed to support email and password, Google and Microsoft sign-in, and enterprise single sign-on (SAML/OIDC) as an enterprise control.
- Email and passwordPlanned
- Google sign-inPlanned
- Microsoft sign-inPlanned
- Enterprise SSO (SAML / OIDC)Enterprise control
No security certifications or attestations are claimed. This describes planned architecture.
Overview
Ten areas of the security design.
Security overview
Designed around least privilege, isolation between workspaces and auditability.
Authentication
Email sign-in, Google and Microsoft options, and enterprise SSO are planned.
Planned
Authorization
Permissions checked at workspace and workflow level.
Designed
Encryption
Designed to protect data in transit and at rest.
Designed
Credential protection
Secrets stored separately, masked after entry and kept out of logs.
Designed
Audit logs
A planned record of who changed and ran what, and when.
Planned
Access control
Roles for owners, admins, builders, approvers and viewers.
Designed
Monitoring
Operational monitoring and alerting for platform health.
Planned
Data handling
Retention and location controls will be documented before general availability.
Planned
Enterprise controls
Enterprise controls can include SSO, granular permissions and extended audit retention.
Enterprise
Compliance status
No certifications are claimed.
FLOWTYPE has not completed any compliance programme or third-party audit. We do not display certification badges.
If and when a certification or attestation is achieved, it will be announced on this page with its scope and date. Until then, treat this page as a description of design intent.
Have security requirements for a specific evaluation? Contact sales and tell us what you need to see.
TALK TO US ABOUT SECURITY.
Tell us about your identity, data handling and audit requirements.