Automation your IT and compliance teams can review in one sitting
The facts security reviewers ask for, in one place: encryption, access controls, certifications, data handling, and sub-processors. Everything here is backed by our Privacy Policy, Terms of Service, and Data Processing Agreement.
Security measures
Encryption in transit
All data between you and the platform is encrypted with TLS 1.2 or higher.
Encryption at rest
Customer content and sensitive account data are encrypted at rest with AES-256 or equivalent.
BYOK credential handling
Your AI provider API keys are encrypted at rest and display masked in the platform UI, with reveal available only to authorized users of your account.
Internal access controls
Internal access to personal data is restricted to authorized personnel on a need-to-know basis, with multi-factor authentication required.
Infrastructure security
Hosted in SOC 2-audited DigitalOcean data centers with firewalls, intrusion detection, network segmentation, and a regular patching schedule.
Data segregation
Customer data is logically segregated to prevent cross-customer access.
Compliance
SOC 2
SOC 2 Type II certification is in progress; customers will be notified upon completion. Cloud infrastructure already runs in SOC 2-audited data centers.
HIPAA
Business Associate Agreements are available for customers processing protected health information. A BAA must be executed before processing PHI. Contact legal@flowrunner.ai.
GDPR and privacy law
Our Data Processing Agreement covers GDPR, UK GDPR, the Swiss FADP, CCPA/CPRA, and the Texas Data Privacy and Security Act, and incorporates the EU Standard Contractual Clauses for international transfers.
Audit trails and platform controls
Execution logs on every plan (7 days on Growth), audit trails on Professional (30 days) and Business (90 days), unlimited retention on Enterprise. Role-based access control from Professional; SSO via SAML 2.0 (Okta, Azure AD, Google Workspace, OneLogin) from Business. See pricing for the full matrix.
Human oversight by design
Workflows pause for human judgment at the decision points you define, and the decision trail lands in the audit log. How human-in-the-loop works.
Sub-processors
Current sub-processors for cloud deployments. We provide at least 30 days' notice before adding or replacing a sub-processor that processes customer content.
DigitalOcean
Cloud infrastructure hosting and compute services.
MongoDB
Database services.
Redis
Caching and session management.
Data handling
BYOK means your data goes direct
Workflow data sent to AI providers travels directly to them using your credentials. FlowRunner does not control, monitor, or have visibility into it.
Retention and deletion
On termination, customer content is retained in a paused state for 30 days for reactivation, export, or deletion. Encrypted backup copies are purged within 90 days of deletion from active systems.
Self-hosted option
The free Community Edition and Enterprise self-hosted run entirely on your infrastructure. FlowRunner has no access to customer content on self-hosted installations.
Frequently asked questions
Is FlowRunner SOC 2 certified?
FlowRunner is pursuing SOC 2 Type II certification and will update customers upon completion. Cloud infrastructure already runs in SOC 2-audited data centers operated by DigitalOcean.
Does FlowRunner sign HIPAA Business Associate Agreements?
Yes. Customers processing protected health information must execute a BAA before processing PHI through the platform. Contact legal@flowrunner.ai to initiate one.
How is my data encrypted?
All data in transit is encrypted with TLS 1.2 or higher. Customer content and sensitive account data are encrypted at rest using AES-256 or equivalent. BYOK API keys are encrypted at rest and display masked in the platform UI.
Can FlowRunner see the data my workflows send to AI providers?
No. Under the BYOK model, workflow data is transmitted directly to your AI providers using your own credentials. FlowRunner does not control, monitor, or have visibility into data sent to third-party AI providers through your API keys.
Is FlowRunner GDPR compliant?
FlowRunner offers a Data Processing Agreement covering GDPR, UK GDPR, the Swiss FADP, CCPA/CPRA, and the Texas Data Privacy and Security Act, with EU Standard Contractual Clauses for international transfers. The DPA is published at flowrunner.ai/data-processing.
Where is FlowRunner data hosted?
Cloud deployments run on DigitalOcean infrastructure in SOC 2-audited data centers, with MongoDB for database services and Redis for caching and session management. Customer data is logically segregated between customers.
What happens to my data if I cancel?
Customer content is retained in a paused state for 30 days, during which you can reactivate, export, or request deletion. After that it is deleted from active systems; residual copies in encrypted backups are purged within 90 days.
Can I run FlowRunner on my own infrastructure?
Yes. The self-hosted Community Edition is free, and Enterprise self-hosted adds clustering and the full compliance suite. On self-hosted deployments FlowRunner has no access to or visibility into your customer content.
Security questionnaire, architecture review, or an IT-specific call: contact us or email legal@flowrunner.ai.
Bring your IT team
A 30-minute walkthrough covering architecture, deployment options, and the compliance controls, with the people who built it.