What's New
This page records changes that affect the people who use flowscope: the platform that runs every product, what the capture stack does on participant machines, our security and privacy commitments, and any planned maintenance that could interrupt access. Entries are posted newest first, each dated with when it took effect.
How customers are notified
This page is the canonical record, and two kinds of change are also sent to customers directly:
- New subprocessors are notified in writing before they begin processing customer data, on the timeline set out in the Data Processing Addendum. To subscribe, email
security@flowscope.comwith the subject line "Subscribe: subprocessor changes" and your organization name. The current list and its history are on the subprocessors page. - Security incidents affecting Customer Data are notified to the customer contact without undue delay, within the timeframe committed in the applicable agreement (72 hours by default). The process is described in the security and trust overview.
Planned maintenance that could interrupt access is posted here ahead of the window.
Change log
2026-08-11 · SOC 2 Type I report issued
Johanson Group LLP issued flowscope's SOC 2 Type I report on August 10, 2026. The report covers the Security Trust Services Criteria and opines on the design of our controls as of May 31, 2026. The Type II examination continues, with an observation window that closes on August 31, 2026. The report is restricted-use and is available to customers and prospects under NDA on request via security@flowscope.com. The FAQ and the compliance summary on the trust center home reflect the new status.
2026-07-30 · Presence signal gains one fact of shape: browser or not
The content-free presence signal recorded while a participant works outside the captured scope (the 2026-07-16 entry below) now carries one additional fact: whether the uncaptured foreground software was a web browser. The check runs on the participant's device against a fixed list of known browsers; the signal still carries no application or site identity beyond that single yes-or-no, no titles, no keystrokes, and no content. The customer can now see how much active time outside the captured scope was in a browser versus other software, but still never which application, site, or page it was. Denylisted software remains indistinguishable from any other uncaptured software of the same kind. What is captured inside the allowlist is unchanged. The Discovery trust addendum and the categorical denylist page describe the capture boundary in full.
2026-07-16 · Content-free presence signal for activity outside the allowlist
During a Discovery engagement, the desktop agent and the browser extension now record a content-free presence signal while a participant is actively working in an application or site that is not captured, whether it is outside the customer-configured allowlist or on the categorical denylist. The signal carries only the span of time involved, with no application or site identity, no titles, no keystrokes, and no content, so the engagement can distinguish active time in uncaptured software from time away from the machine without learning what that software was. Where a presence span covers time in denylisted software it is indistinguishable from any other uncaptured software, and a locked, asleep, or idle machine produces no signal at all. What is captured inside the allowlist is unchanged. The Discovery trust addendum and the categorical denylist page describe the capture boundary in full.
2026-06-12 · Form-control state and web request metadata in browser capture
During a Discovery engagement, the browser extension now records two further technical signals inside the customer-configured allowlist: the state of form controls (selected options and entered values, with password fields always dropped), and the technical metadata of the web requests in-scope applications make (method, address, and response status, never the contents), which distinguishes a step that wrote to a system of record from one that only read from it. Both stay inside the same controls as every other capture surface: the customer-configured allowlist, the categorical denylist that overrides it, password values dropped at source, and on-device redaction before anything leaves the machine. The Discovery trust addendum describes those controls in full.
2026-06-04 · A place to follow system updates
This page is now the single place to follow changes to the platform, the capture stack, and our customer commitments. The direct notifications for new subprocessors and security incidents, described above, continue alongside it.
2026-06-03 · Incident notification within 72 hours
A security incident affecting Customer Data is notified to the customer contact in writing within 72 hours of flowscope becoming aware of it, whether or not the data involved was already redacted or pseudonymized. The commitment is reflected in the security and trust overview, the Master Services Agreement, and the Data Processing Addendum.
2026-06-02 · Subprocessor disclosures expanded
The subprocessors page now states, for each third party, the data it touches, the region it runs in, and how long it retains data, including the retention posture of the providers that handle AI inference, redaction, and document parsing.
2026-06-02 · Excel capture during Discovery
During a Discovery engagement, the desktop capture agent can now record spreadsheet edits as they happen, so a process that runs through Excel can be reconstructed more accurately. It stays inside the same controls as every other capture surface: the customer-configured allowlist, the categorical denylist that overrides it, and on-device redaction before anything leaves the machine. The Discovery trust addendum describes those controls in full.