Before you roll out

Frequently asked questions

All docs

The questions procurement, security, and employment counsel ask most often when evaluating flowscope.

Compliance

Are you SOC 2 certified? Our SOC 2 Type I report was issued by Johanson Group LLP in August 2026, covering the Security Trust Services Criteria. The Type II examination is underway. The Type I report and compliance documentation from our subprocessors are available under NDA on request.

Are you HIPAA-compliant? Protected health information is Excluded Restricted Data: the customer keeps it out of the observation scope unless a Business Associate Agreement applies to the engagement. Contact legal@flowscope.com to scope.

Do you offer GDPR coverage? flowscope is United States by default, and a GDPR compliance program is underway on the same continuously monitored footing as SOC 2. Deployments involving European Union or United Kingdom personnel are processed under the customer agreement, which incorporates the EU Standard Contractual Clauses and the UK Addendum; workplace-monitoring notices and consents rest with the customer. Contact legal@flowscope.com to scope.

What about CCPA and CPRA? flowscope acts as a Service Provider under the CCPA and CPRA. flowscope does not sell or share personal information, does not use it for cross-context behavioral advertising, and does not use it for any purpose other than performing the Services. flowscope notifies the customer of any data-subject request it receives and assists the customer's response, so the customer, as the Business, can respond within the timeframes required by applicable law (the 45-day response period under the CCPA and CPRA, extendable by a further 45 days where reasonably necessary). Contact legal@flowscope.com.

What we collect

What does the capture software collect? Inside the business applications and domains on the customer's allowlist, the software captures interaction metadata (clicks, paste actions, time-in-system, field transitions, window and tab titles, URLs with authentication tokens stripped), user interface text, the state of form controls (selected options and entered values, with password fields always dropped), the text of documents and files opened in allowlisted applications, extracted on the device, email content from allowlisted email applications including subject lines and bodies, clipboard content from copy and paste actions, modifier-bearing keystrokes and named keys, a user identifier and device identifier, and device and session metadata. Where an application has no accessible text, or is a canvas web application, its screen text is captured through screenshots, kept to a minimum. Outside the allowlist, the software collects two narrow signals: a content-free presence span recording how long a participant was actively working in uncaptured software and whether that software was a web browser, carrying no further application or site identity, no titles, and no content, and a one-time report of the bare name of an unlisted application or domain to the customer admin's scoping review, carrying no usage timing, no duration, and no link to any participant. Denylisted software appears in neither report by name.

Who decides what goes on the allowlist? The customer does, and the customer can change it at any time. flowscope proposes the initial list from the systems the customer names for the workflows in scope, and the customer confirms, amends, or replaces it. During the engagement flowscope keeps the list current on the customer's authority: business systems that fall inside the confirmed workflow scope are added, and anything that cannot be placed with confidence waits for the customer admin to accept or reject it. Adding a system never enables screen capture, which is a separate clearance, and nothing added by either party can override the denylist. The customer admin can switch the automatic additions off on the allowlist page, after which every addition waits for their decision; switching it off does not remove what is already on the list. Monitoring the list and deciding the referred items during the engagement is the customer's responsibility, because a business system left waiting is a workflow missing from the result.

What is the denylist exactly? The list of applications and sites the capture software never records in an organization; it overrides the customer-configured allowlist. Every organization starts from flowscope's default list, and its administrators add entries from the dashboard; the default entries stay on every list. The seven default categories are banking, brokerage, and consumer payments (examples include Chase, Fidelity, Schwab, Robinhood, Coinbase); healthcare portals, electronic-health-record vendors, insurers, and hospital systems; password managers (examples include 1Password, Bitwarden, LastPass, Dashlane, Apple Passwords, browser built-ins); encrypted messengers (examples include Signal, WhatsApp Web, Telegram Web, iMessage, Matrix clients); consumer and personal email; legal research, court filing, and case-management portals; and government services portals. In addition to these categories, content-level drops exclude private and incognito browser windows and strip authentication token parameters from URLs. See the categorical denylist page for the default list.

Do you record video or screen captures? No screen recording. Still screenshots apply to applications without accessible text (for example terminal emulators and certain legacy or remote-desktop sessions) and to canvas web applications, and are kept to a minimum. These screenshots are subject to the same redaction and scope controls as the rest of the captured data. An organization's administrators can switch screen capture off for all of the organization's applications from the dashboard.

Do you log keystrokes? Only modifier-bearing keystrokes and named control keys (Tab, Escape, arrow keys, function keys, and modifier-based shortcuts) are captured; plain alphanumeric keystrokes are never recorded.

What if an employee uses their personal laptop? The desktop application is installed by the customer's IT team on customer-owned devices in the participating cohort. The customer agreement provides for deployment on workstations the customer manages.

What if a personal file is opened inside an allowlisted business application? On detection of the file open or document interaction, the capture software classifies the file as work material for the engagement by default and gives the participating employee a bounded decline period, shown on the device with the time remaining, to mark the file personal. A file marked personal is discarded on the device and its contents never leave it; if the period lapses, the text and logic the device extracts from the file are sent as work material. File-open metadata is recorded for a file that settles as work, with personal-data entities detected within file names redacted server-side before storage; while a file is still within its decline period, that metadata is held on the device and is sent only if the file settles as work.

Data handling

Where is the data stored? United States. Customer data is stored and processed only in United States regions. The services that touch customer data are listed on Subprocessors.

How is captured personal data redacted? A two-layer pipeline that runs on every Discovery deployment. The on-device layer runs at the point of capture and applies format and checksum validation to standard PII categories (payment-card numbers, bank-account identifiers, government-issued identification numbers); only redacted content leaves the workstation. The server-side layer runs before persistence and uses Microsoft Azure AI Language (PII detection) to identify and replace a broader set of named entities (personal names, organization names, postal addresses, dates of birth, and the other entity categories Azure AI Language is configured to detect) with type-tagged placeholders. The server-side layer is always on.

How are employee identities handled? Every person shows as a masked letter label ("Person A") by default across the Discovery product. An organization admin or a flowscope sysadmin can turn real names on, on their own screen, and flowscope records every reveal in an audit trail. The analysis pipeline works with letter labels. Deliverables aggregate at the workflow level, as process maps, not individual performance scores.

Can we export our data? Yes. On written request, flowscope provides a structured machine-readable export (CSV or JSON).

Can the customer revoke access immediately? Yes. The organization's admins revoke any device from the dashboard; it stops capturing and cannot upload. flowscope can also deactivate remotely. Physical uninstallation from the device is the customer's responsibility but can be performed by the employee at any time without flowscope's involvement.

Security operations

Who at flowscope has access to customer data? A named subset of @flowscope.com operators, federated through Google Workspace with MFA enforced. Operational access to customer-data systems is logged through the internal monitoring pipeline. For support, an operator can impersonate a customer user inside the application; the impersonation is attributed to the operator and shown by an in-session banner while it is active.

Do you do penetration testing? Yes. Oneleet performs flowscope's annual penetration test; the June 2026 test covered the web application and the Windows desktop application (OWASP WSTG). The report is available under NDA on request. In parallel, CodeQL code scanning runs on every pull request through GitHub's default setup, with secret scanning and Dependabot security updates; application dependencies are scanned continuously with security advisories triaged within seven days for high-severity issues, and the production environment is monitored continuously through centralized logging and observability.

Do you have a vulnerability disclosure policy? Yes. Suspected vulnerabilities go to security@flowscope.com. Acknowledgement within two business days; remediation timeline depends on severity, with critical issues targeted within seven days and high-severity within thirty days. A machine-readable contact record is available at flowscope.com/.well-known/security.txt.

Contracts

Do you sign DPAs? Yes. The customer agreement includes data-processing terms that cover CCPA and CPRA Service Provider obligations, and flowscope reviews and signs a customer's own data processing agreement where the terms are materially equivalent.

Reaching us

  • General security questions: security@flowscope.com
  • Compliance, privacy, and legal questions: legal@flowscope.com
  • Architecture and technical implementation: Javier Leguina, CTO, via security@flowscope.com