Frequently asked questions
The questions procurement, security, and employment counsel ask most often when evaluating flowscope. Answers reflect the current state of the platform and the legal pack. Where a question is unresolved or subject to a separate addendum, that is stated explicitly.
Compliance
Are you SOC 2 certified? Our SOC 2 Type I report was issued by Johanson Group LLP in August 2026. It covers the Security Trust Services Criteria as of May 31, 2026. The Type II examination is underway, with the observation window closing August 31, 2026 and issuance following. The Type I report and compliance documentation from our subprocessors are available under NDA on request.
Are you ISO 27001 certified? Not currently. ISO 27001 is on the roadmap behind SOC 2 and will be reviewed once Type 2 issuance is complete.
Are you HIPAA-compliant?
flowscope does not capture protected health information by default. The Master Services Agreement carves out PHI from the scope of Captured Personal Data, and a separate Business Associate Agreement is required before any engagement that involves PHI. Contact legal@flowscope.com to scope.
Do you offer GDPR coverage?
flowscope is United States by default, and a GDPR compliance program is underway on the same continuously monitored footing as SOC 2. Deployments involving European Union or United Kingdom-based personnel currently require a separate addendum addressing GDPR Article 88 and any required works council consultation. Contact legal@flowscope.com to scope.
What about CCPA and CPRA?
flowscope acts as a Service Provider under the CCPA and CPRA. flowscope does not sell or share personal information, does not use it for cross-context behavioral advertising, and does not use it for any purpose other than performing the Services. As a Service Provider, flowscope does not respond to employee data-subject requests directly: it promptly notifies the customer of any such request it receives and provides reasonable assistance so the customer, as the Business, can respond within the timeframes required by applicable law (the 45-day response period under the CCPA and CPRA, extendable by a further 45 days where reasonably necessary). Contact legal@flowscope.com for the Data Processing Addendum.
What we collect
What does the capture software collect? Inside the business applications and domains on the customer's allowlist, the software captures interaction metadata (clicks, paste actions, time-in-system, field transitions, window and tab titles, URLs with authentication tokens stripped), user interface text, the state of form controls (selected options and entered values, with password fields always dropped), the technical metadata of web requests made by in-scope applications (method, address, and response status, never the contents), document and file content, email content from allowlisted email applications including subject lines and bodies, clipboard content from copy and paste actions, modifier-bearing keystrokes and named keys, a pseudonymous user identifier and device identifier, and device and session metadata. Where other capture methods are not available, occasional screenshots from a narrow set of applications such as terminal emulators may be contracted separately with the customer. Outside the allowlist, the software collects two narrow signals: a content-free presence span recording how long a participant was actively working in uncaptured software and whether that software was a web browser, carrying no further application or site identity, no titles, and no content, and a one-time report of the bare name of an unlisted application or domain to the customer admin's scoping review, carrying no usage timing, no duration, and no link to any participant. Denylisted software appears in neither report by name. See the Discovery Trust Addendum for the full breakdown.
What does the capture software not collect? Outside the customer-configured allowlist, and in everything on the hardcoded denylist (banking, brokerage, and consumer payments; healthcare portals, electronic-health-record vendors, insurers, and hospital systems; password managers; encrypted messengers; consumer and personal email; legal research, court filing, and case-management portals; government services portals), the software never records which application or site was being used, any window or tab title, or any content; active time there is at most reflected in the content-free presence span described above, which carries one fact of shape (whether the foreground software was a web browser) and within which denylisted software is indistinguishable from any other uncaptured software of the same kind; some denylisted contexts, such as private browsing windows that the browser hides from extensions, produce no signal at all. In addition to these categories, content-level drops exclude private and incognito browser windows and strip authentication token parameters from URLs. Beyond that, the software does not collect authentication tokens, password fields, audio, video, biometric identifiers, continuous keystroke logging, recipient fields in emails, device IP address, device geolocation, or any file the participant marks personal during the per-file decline window, which leaves no record at all, neither its contents nor any metadata about it, all of which is discarded on the device and never leaves it. File-open metadata for files that settle as work in allowlisted applications (a salted file identifier and a salted folder identifier, the file name, type, and size, the application that opened the file, and the work classification) is recorded, with personal-data entities detected within file names redacted server-side before storage; for a file still within its window it is held on the device and sent only if the file settles as work. See the Discovery Trust Addendum for the full breakdown.
Who decides what goes on the allowlist? The customer does, and the customer can change it at any time. flowscope proposes the initial list from the systems the customer names for the workflows in scope, and the customer confirms, amends, or replaces it. During the engagement flowscope keeps the list current on the customer's authority: business systems that fall inside the confirmed workflow scope are added, and anything that cannot be placed with confidence waits for the customer admin to accept or reject it. Adding a system never enables screen capture, which is a separate clearance, and nothing added by either party can override the denylist. The customer admin can switch the automatic additions off on the allowlist page, after which every addition waits for their decision; switching it off does not remove what is already on the list. Monitoring the list and deciding the referred items during the engagement is the customer's responsibility, because a business system left waiting is a workflow missing from the result.
What is the denylist exactly? A hardcoded list of application and context categories that override the customer-configured allowlist regardless of how the customer admin configures it. The seven default categories are banking, brokerage, and consumer payments (examples include Chase, Fidelity, Schwab, Robinhood, Coinbase); healthcare portals, electronic-health-record vendors, insurers, and hospital systems; password managers (examples include 1Password, Bitwarden, LastPass, Dashlane, Apple Passwords, browser built-ins); encrypted messengers (examples include Signal, WhatsApp Web, Telegram Web, iMessage, Matrix clients); consumer and personal email; legal research, court filing, and case-management portals; and government services portals. In addition to these categories, content-level drops exclude private and incognito browser windows and strip authentication token parameters from URLs. See the categorical denylist page for the authoritative enumeration. The customer admin can extend the denylist with categories specific to their business; neither the admin nor flowscope can shrink it below the default.
Do you record audio? No. flowscope does not capture microphone audio. The capture model is based on accessibility-tree events and document content within allowlisted applications, not pixels and not audio.
Do you record video or screen captures? No screen recording. Still screenshots are off by default and are contracted separately with the customer. They are enabled only for a named narrow set of applications where other capture methods are not available (for example terminal emulators and certain legacy or remote-desktop sessions). These screenshots are subject to the same redaction and scope controls as the rest of the captured data.
Do you log keystrokes? Only modifier-bearing keystrokes and named control keys (Tab, Escape, arrow keys, function keys, and modifier-based shortcuts) are captured; plain alphanumeric keystrokes are never recorded, and the software is structurally incapable of acting as a keystroke logger.
What if an employee uses their personal laptop? The agent is installed by the customer's IT team on customer-owned devices in the participating cohort. flowscope does not provide or recommend installation on personal devices, and the Statement of Work expects deployment on workstations the customer has the authority to manage.
What if a personal file is opened inside an allowlisted business application? On detection of the file open or document interaction, the capture software classifies the file as work material for the engagement by default and gives the participating employee a bounded decline period, shown on the device with the time remaining, to mark the file personal. A file marked personal is discarded on the device and its contents never leave it; if the period lapses, the file's bytes upload as work material. File-open metadata is recorded for a file that settles as work, with personal-data entities detected within file names redacted server-side before storage; while a file is still within its decline period, that metadata is held on the device and is sent only if the file settles as work.
Data handling
Where is the data stored? United States. Customer data is stored and processed only in United States regions, and flowscope does not store customer data outside the United States. The services that touch customer data, with their per-service retention terms, are listed on Subprocessors.
Do you train AI models on customer data? No. Customer data is not used to train, fine-tune, or otherwise develop any AI or machine-learning model without the customer's prior written consent. Customer data is never retained in any AI provider training pipeline. The per-service retention terms are stated on the Subprocessors page; where a provider holds transient analysis data, flowscope deletes it promptly, within the provider's stated retention window.
How is captured personal data redacted? A two-layer pipeline that runs on every Discovery deployment under MSA §6.7. The on-device layer runs at the point of capture and applies format and checksum validation to standard PII categories (payment-card numbers, bank-account identifiers, government-issued identification numbers); only redacted content leaves the workstation. The server-side layer runs before persistence and uses Microsoft Azure AI Language (PII detection) to identify and replace a broader set of named entities (personal names, organization names, postal addresses, dates of birth, and the other entity categories Azure AI Language is configured to detect) with type-tagged placeholders. The server-side layer is always on. Where personal data cannot be isolated for redaction without deleting the surrounding record, the entire record is deleted. See the Discovery Trust Addendum for the architecture in full.
How does pseudonymization work? Each in-scope employee is identified within Customer Data by a pseudonymous User ID derived from a per-organization salt held by the customer. flowscope holds a copy of that salt only during setup and destroys it when capture begins, after which it cannot reconstruct the relationship between any User ID and the corresponding employee identity. The property is architectural rather than operational: flowscope does not hold the inputs required to perform the reverse mapping.
How long do you keep the data? For the duration of the customer's contract, the database retains the captured data and the records of how flowscope has processed it. After contract termination, the customer can retrieve their data in electronic format for thirty days. Deletion is performed on customer request: the customer can request deletion at any time after termination, including zero-day deletion on termination, and flowscope provides written certification of a completed deletion on request. The applicable agreement governs the retention terms.
Can we export our data? Yes. On written request during an active engagement, flowscope provides a structured machine-readable export (CSV or JSON) within ten business days. After contract termination, the customer can retrieve data in electronic format for thirty days. See the Discovery Trust Addendum and the Data Processing Addendum for the full terms.
Can the customer revoke access immediately? Yes. flowscope can remotely deactivate the agent at any time on customer request; deactivation takes effect on all in-scope devices that have a live network connection. Physical uninstallation from the device is the customer's responsibility but can be performed by the employee at any time without flowscope's involvement.
Security operations
Who at flowscope has access to customer data?
A named subset of @flowscope.com operators, federated through Google Workspace with MFA enforced. Operational access to customer-data systems is logged through the internal monitoring pipeline. For support, an operator can impersonate a customer user inside the application; the impersonation is attributed to the operator and shown by an in-session banner while it is active.
Do you do penetration testing? Yes. Independent third-party penetration testing is performed as part of the SOC 2 examination; the most recent test was completed in 2026 and its findings have been remediated. The report is available under NDA on request. In parallel, static analysis runs on every pull request, application dependencies are scanned continuously with security advisories triaged within seven days for high-severity issues, and the production environment is monitored continuously through centralized logging and observability.
Do you have a vulnerability disclosure policy?
Yes. Suspected vulnerabilities go to security@flowscope.com. Acknowledgement within two business days; remediation timeline depends on severity, with critical issues targeted within seven days and high-severity within thirty days. A machine-readable contact record is available at flowscope.com/.well-known/security.txt.
Contracts
Do you sign DPAs? flowscope's Data Processing Addendum is incorporated as Exhibit B to the Master Services Agreement and covers CCPA and CPRA Service Provider obligations. flowscope is open to reviewing customer-paper DPAs and signing a customer's DPA where the terms are materially equivalent.
Reaching us
- General security questions:
security@flowscope.com - Compliance, privacy, and legal questions:
legal@flowscope.com - Architecture and technical implementation: Javier Leguina, CTO, via
security@flowscope.com