flowscopeTrust Center
flowscope Trust Center

The security and privacy posture behind the agents we ship.

flowscope builds agents that map, redesign and automate business processes, which means that part of what we do involves observing how employees actually use their business applications. Because that work is unusually load-bearing on trust, the documents in this center describe what we collect and what we do not, how the platform is built and operated, how customers verify our claims, and where the legal commitments live.

AICPA SOC for Service Organizations mark. flowscope's SOC 2 Type I report was issued in August 2026.
flowscope GDPR compliance badge, independently verified by Oneleet
AI data handling

No AI training

No training on customer data. OpenAI inference under contractual Zero Data Retention.

Hosting

United States only

Customer data is processed and stored only in the United States.

Encryption

TLS 1.3 · AES-256

TLS 1.3 in transit, AES-256 at rest, on every data store.

Incident response

72-hour notice

Written notice within 72 hours of flowscope becoming aware.

Start here

One place to start, for each person an engagement touches.

Each opens with a short video, answers that audience’s own questions in plain language, and cites the document behind every claim. The rest of that audience’s guides follow beside it.

Documents & controls

The documents we publish, and the live controls that back them.

These pages describe how flowscope secures customer data, respects employee privacy, and runs the platform that delivers agents into production, covering hosting, encryption, retention, the capture stack, and how customers verify each claim for themselves.

Security and Trust Overview

Hosting and deployment models, model providers, encryption, authentication, retention, backups, and incident response for the platform that runs every flowscope product.

Read the page

Discovery Trust Addendum

Capture-stack controls during the time-boxed Discovery engagement: customer-controlled allowlist, categorical denylist, on-device redaction, pseudonymized identifiers, and the participant transparency surface.

Read the page

Workflow Execution Addendum

Reviewer scoping, human authorization, audit logging, and customer-issued credentials for workflows that act on systems of record.

Read the page

Retrieval-Augmented Generation Addendum

Ingestion controls, query auditing, and source attribution for retrieval-augmented chat surfaces over customer documents.

Read the page

Categorical denylist

The always-deny categories that flowscope's capture surfaces enforce before any event payload is constructed, overriding any allowlist the customer admin configures.

Read the page

Subprocessors

Every third party that may process customer data, what it touches, and how customers stay informed when the list changes.

Read the page

What's New

The channel where flowscope records changes to the platform, the capture stack, our security and privacy commitments, and any planned maintenance, so customers learn about anything that affects them.

Read the page

Questions procurement and security ask

Questions procurement, security, and employment counsel ask most often. Employees have their own set, on the page written for them.

Read the page
Policy package

Information security policies.

The formal policy set behind the SOC 2 program, covering the AICPA Trust Services Criteria, available on request. Request the complete package in one submission below, or email security@flowscope.com.

On request
Vulnerability disclosure

Found something we should know about?

Send suspected security issues to security@flowscope.com. We acknowledge within two business days; critical issues are remediated within seven days, high severity within thirty.