Flowviant Sign in Start free
← Back to home

Security

How we protect your data and run the Service.

Last updated August 18, 2026

Security is built into how Flowviant is architected and operated. This page summarizes our practices. If you discover a vulnerability, please report it (see below) — we appreciate responsible disclosure.

Infrastructure

Flowviant runs entirely on Cloudflare's global network — application logic on Workers, the relational store on D1, and large objects on R2. We benefit from Cloudflare's DDoS protection, WAF, and physically secured data centers.

Encryption

  • In transit. All traffic to and from the Service is encrypted with TLS.
  • At rest. Data stored in our database and object storage is encrypted at rest by our infrastructure provider.

Authentication

Accounts and sessions are managed by Flowviant directly. We support OAuth sign-in with GitHub and Google, or a one-time code emailed to you — there are no passwords at all, so there is no password of yours for us to store, leak, or be phished for. Sessions are first-party cookies scoped to app.flowviant.com.

Payments

Paid plans aren't live yet. When they are, payments will be processed by Stripe, a PCI-DSS Level 1 certified provider, and Flowviant will never see or store full card numbers.

Access and permissions

Your code changes are pushed from your own machine by the Flowviant daemon — Flowviant holds no standing access to your repositories. The daemon acts under a project credential you can revoke at any time. Access is granted PER PROJECT: somebody you invite to one project cannot see or open another. Removing someone ends their open Terminal tabs and New task chats and revokes their session tokens; a machine they connected keeps serving the project until somebody disconnects it in Project settings › Machines.

AI data handling

Coding work runs on your own machine, under your own AI logins. Flowviant's servers run one model: the optional ship review quiz, which sends the change under review to Google Gemini when a quiz is made. Nothing else on our servers summarises or generates.

Backups and resilience

Our database supports point-in-time recovery, and our infrastructure is designed for high availability across Cloudflare's network.

Reporting a vulnerability

If you believe you've found a security issue, email security@flowviant.com with details and steps to reproduce. Please give us a reasonable opportunity to address it before any public disclosure. We will not pursue action against good-faith research that respects user privacy and avoids service disruption.

Subprocessors

The third parties that process data on our behalf are listed in our Privacy Policy.