The security page your
compliance team is asking for.
flow8 runs on your infrastructure. Encrypted at rest. Granular access controls. A complete audit trail on every execution. Nothing leaves without your permission.
Security is the architecture, not a feature.
Regulated teams don't need a checkbox. They need a system where sensitive data has nowhere to go but where it's supposed to.
Every execution leaves a complete record.
When an auditor asks what happened to a record, the answer is already there — timestamped, attributed, immutable. flow8 logs every step of every run. You don't reconstruct the trail. You just export it.
- ✓ Step-level logs for every execution
- ✓ Input and output data recorded per step
- ✓ User attribution on every trigger and action
- ✓ Timestamps on every state change
- ✓ Exportable for compliance reporting
A breach exposes nothing useful.
Sensitive fields are encrypted before they're written to the database. The encryption key is yours — managed in your environment, never transmitted to flow8. If someone gets the database, they get ciphertext.
- ✓ Field-level encryption on sensitive data
- ✓ Keys managed entirely in your environment
- ✓ Encrypted values never appear in logs
- ✓ Credentials injected at runtime only
Every user sees exactly what their role allows.
Access is enforced at the API layer — not just hidden in the UI. Roles are scoped to the company entity, so multi-tenant deployments stay fully isolated. An employee in one business unit cannot see or trigger flows owned by another.
- ✓ Company-scoped multi-tenancy
- ✓ Role-based access enforced at API level
- ✓ Separate permissions for view, run, edit, admin
- ✓ API key authentication for integrations
- ✓ OAuth2 support for enterprise SSO
Deployed where your security policy requires.
No forced cloud. No shared infrastructure. flow8 runs wherever your data is allowed to live.
Built for regulated industries.
The teams with the strictest compliance requirements are exactly who flow8 was built for.
flow8 does not process, store, or transmit your data to any external system. All execution happens inside your deployment. Compliance obligations stay with you — not with a vendor who has access to your records.
Send this to your security team.
Book 30 minutes and we'll walk them through the architecture — deployment model, encryption, access controls, and audit trail — whatever they need to sign off.