flow

Designed to pass the review of a bank's security team — then deployed everywhere else.

Conversations carry identity, money and personal data. The platform is built on the assumption that a second line, a third line and a regulator will read the log. This page describes the controls; the detailed documentation is shared with partners and customers under NDA.

100%of agent actions logged with actor, policy version, inputs and outcome
0customer data on employees' personal devices — the desk is the channel
3deployment models: shared cloud, private cloud, dedicated inside your boundary
1audit trail across channels, agents, staff, components and customer-built code
Controls

What the platform does, by area.

Identity of customers
Verification levels per request type, enforced by the identity agent using OTP, device signals, document + liveness, voice biometrics or your identity provider. Level and method are recorded on every action. Step-up is triggered by policy and by risk score, never left to the conversation designer.
Identity of staff and partners
SSO via SAML/OIDC, SCIM provisioning, MFA enforcement, role-based permissions down to field level. Build permission, policy ownership, approval rights and administration are separate roles. Partner administrators act within the estates they are granted.
Tenant isolation
Each tenant has its own data boundary, keys, component enablement, policies and users. Customer-built capabilities execute within the tenant boundary with the tenant's permissions; they cannot address other tenants. Group views exist only where explicitly granted.
Encryption & keys
Encryption in transit and at rest; field-level encryption for sensitive form fields with a master key the customer can hold; key rotation with overlap windows so live integrations don't break. Private and dedicated deployments use the customer's key management.
Data residency & model routing
Hosting region per tenant. Model inference routed by data class — flow's Claude cloud, the customer's own provider contract, or private inference inside the customer's boundary. Model providers are contracted to exclude training on customer data.
Agent policy & human-in-the-loop
Policy cards define tools, limits, required identity levels and handover rules per agent, segment and channel. Versioned and owned by the business. Simulation on historical conversations before enabling a change. Kill switch per agent and per tenant.
Audit & evidence
Every turn, tool call, input, output, identity event, approval and build is logged with the policy version that allowed it. Export to SIEM and records systems; retention per record type; evidence packs generated from the log for internal audit and regulators.
Customer-built code
Generated in the platform's code base against certified components; passes automated tests and policy checks; review gates configurable per change class; versioned with attribution and instant rollback. Data-access and audit rules are the platform's, not the generated code's.
Channel security
Official WhatsApp Business Platform, verified business accounts, template approval, webhook signature verification. Telephony with recording consent rules per jurisdiction. Email with SPF/DKIM/DMARC on sending domains.
Operational security
Segregated environments, least-privilege access with logged administrative sessions, dependency and vulnerability management, backup and restore tested on schedule, incident response with customer notification commitments in the agreement.
Privacy
Consent and preference records per person and purpose; data-subject request handling built into the record (export, correction, deletion); data minimization in agent context; processing agreements aligned with GDPR and Israeli privacy law, with other regimes handled per deployment.
Assurance
Security documentation, architecture and control descriptions, penetration-test summaries and questionnaires are shared under NDA. Dedicated deployments can be assessed by the customer's own teams.
Shared responsibility

Who controls what.

flow secures the platform and the agent runtime. The customer or partner owns policy, identity levels, component enablement, users and the systems behind connectors. Solution partners typically own the control framework in regulated deployments. The lines are written into the agreement, not left implicit.

AreaflowCustomer / partner
Platform & agent runtimeOwns
Policy cards & identity levelsReference libraryOwns
Component enablement & limitsCertificationOwns
Users, roles, SSOEnforcesOwns
Connected systems & their dataOwns
Infrastructure (private / dedicated)SupportsOwns or delegates
Model provider contractDefaultOptional own contract

Bring your questionnaire.

We'd rather answer the 300 questions before the pilot than after. Request the security pack and a session with our engineering team.