Everything a security review asks, in one place.

This page covers what security reviewers and compliance teams ask us most: certifications, data handling, access control and what happens to your data at every stage. If you need something that isn't here, ask us directly.

Security question? Contact our team →

Where we
stand on SOC 2.

Flowchestra is currently undergoing its SOC 2 Type I examination, working with Thoropass. On completion, we move into the SOC 2 Type II observation period. A letter confirming examination status is available on request.

We won't call ourselves SOC 2 certified, because SOC 2 is an auditor's attestation report, not a certification, and the difference matters in a security review.

1

SOC 2 Type I examination

Currently underway with Thoropass. Letter confirming examination status available on request.

2

SOC 2 Type II observation period

Begins on completion of the Type I examination.

Your data, at every stage.

Where it lives.

Original copies of your data stay in your systems. Where the platform retains copies for processing and availability, they live inside Flowchestra's managed infrastructure, encrypted at rest.

Training.

By default, your data is not used to train AI models. Flowchestra is configured to prevent it, and providers that require data to be used for training can be blocked entirely. If your own policy permits training-enabled models, that stays your choice to make. Data reaches a model only when a user sends a request.

Sensitive data.

When sensitive information appears in a request, it's flagged to the user before anything is sent, including before it moves into any third party system.

When you leave.

If you close your account, your data is retained for 30 days, then removed from our systems through an automated process. If you need a full export, we'll arrange it. Legal holds are the one exception, and you'd be notified.

Who can do what, under your rules.

Access is role based: you decide who can use which models, tools and data. Single sign on connects the platform to your identity provider. Credentials and keys sit in a dedicated vault rather than in workflows. And every significant action is logged, so there's an audit trail behind every answer.

Role based accessWho can use which models, tools and data
Single sign onConnected to your identity provider
Dedicated key vaultCredentials never sit in workflows
Audit trailEvery significant action is logged

The controls themselves live on the platform. See the platform controls →

How the platform is put together.

Flowchestra sits between your business systems and the AI models you choose to use. Governance, access control and logging happen in that layer, which is what makes usage visible and controllable while it happens rather than audited after the fact.

located atusehostconnect tostoresrunstrackscreatePeoplePlacesAppsFlowchestraDocumentsWorkflowsThings
Flowchestra's knowledge graph. The platform sits at the centre of your people, places, apps, documents and workflows, which is the layer governance and logging run in.

The providers behind the platform.

Flowchestra runs on a small set of service providers. The full, current list is below and kept up to date.

Flowchestra's subprocessors: provider, purpose, data processed and location
ProviderPurpose Data processedLocation
The current list is confirmed on request. Ask us and we'll send Flowchestra's subprocessor list directly, with the purpose, data processed and processing location for each provider. Request the list →

Built with regulated environments in mind.

Flowchestra is designed to support the obligations regulated organizations carry: auditability, human oversight, access control and defensible records. The platform's design also aligns with the direction of AI regulation, including the EU AI Act's emphasis on governance, transparency and human oversight.

Regulatory responsibility always stays with your organization. What Flowchestra provides is the operational evidence that makes those responsibilities easier to meet.

Auditability

Every significant action recorded, with the rules that were in force.

Human oversight

Review stays inside the process for higher-risk and client-facing work.

Access control

Role based, connected to your identity provider, keys held in a vault.

Defensible records

Evidence you can put in front of a reviewer, not a reconstruction.

Asked in almost every review.

By default, no. Flowchestra is configured to prevent customer data being used to train models, and providers that require training can be blocked entirely. Organizations whose own policies permit training-enabled models can choose to allow them. Data reaches a model only when a user sends a request, and the model handling it is shown to the user at the time.

Access is restricted and logged. Your data isn't shared with other customers, isn't used for marketing, and internal access is limited to what's required to operate and support the platform.

It's retained for 30 days after account closure for continuity, then removed through an automated deletion process. Exports can be arranged, and legal holds are the only exception to the timeline, with notification.

We answer hosting and data residency questions directly, in writing, because the right answer depends on your requirements and your regulator's. Ask us and you'll get specifics rather than a general statement.

Our incident and breach notification process is something we take you through directly. Ask us and we'll walk you through it.

Yes. Model access is part of the platform's access controls: you decide which models are available, to whom, and with what data.

Put your hardest security question to us.

Bring your security reviewer. We'd rather answer everything live.

Contact our security team →