The security and privacy posture behind the agents we ship.
flowscope builds agents that map, redesign and automate business processes, which means that part of what we do involves observing how employees actually use their business applications. Because that work is unusually load-bearing on trust, the documents in this center describe what we collect and what we do not, how the platform is built and operated, how customers verify our claims, and where the legal commitments live.

No AI training
No training on customer data. OpenAI inference under contractual Zero Data Retention.
United States only
Customer data is processed and stored only in the United States.
TLS 1.3 · AES-256
TLS 1.3 in transit, AES-256 at rest, on every data store.
72-hour notice
Written notice within 72 hours of flowscope becoming aware.
One place to start, for each person an engagement touches.
Each opens with a short video, answers that audience’s own questions in plain language, and cites the document behind every claim. The rest of that audience’s guides follow beside it.
The documents we publish, and the live controls that back them.
These pages describe how flowscope secures customer data, respects employee privacy, and runs the platform that delivers agents into production, covering hosting, encryption, retention, the capture stack, and how customers verify each claim for themselves.
Security and Trust Overview
Hosting and deployment models, model providers, encryption, authentication, retention, backups, and incident response for the platform that runs every flowscope product.
Read the pageDiscovery Trust Addendum
Capture-stack controls during the time-boxed Discovery engagement: customer-controlled allowlist, categorical denylist, on-device redaction, pseudonymized identifiers, and the participant transparency surface.
Read the pageWorkflow Execution Addendum
Reviewer scoping, human authorization, audit logging, and customer-issued credentials for workflows that act on systems of record.
Read the pageRetrieval-Augmented Generation Addendum
Ingestion controls, query auditing, and source attribution for retrieval-augmented chat surfaces over customer documents.
Read the pageCategorical denylist
The always-deny categories that flowscope's capture surfaces enforce before any event payload is constructed, overriding any allowlist the customer admin configures.
Read the pageSubprocessors
Every third party that may process customer data, what it touches, and how customers stay informed when the list changes.
Read the pageWhat's New
The channel where flowscope records changes to the platform, the capture stack, our security and privacy commitments, and any planned maintenance, so customers learn about anything that affects them.
Read the pageQuestions procurement and security ask
Questions procurement, security, and employment counsel ask most often. Employees have their own set, on the page written for them.
Read the pageInformation security policies.
The formal policy set behind the SOC 2 program, covering the AICPA Trust Services Criteria, available on request. Request the complete package in one submission below, or email security@flowscope.com.
Found something we should know about?
Send suspected security issues to security@flowscope.com. We acknowledge within two business days; critical issues are remediated within seven days, high severity within thirty.