Security is built into how Flowviant is architected and operated. This page summarizes our practices. If you discover a vulnerability, please report it (see below) — we appreciate responsible disclosure.
Infrastructure
Flowviant runs entirely on Cloudflare's global network — application logic on Workers, the relational store on D1, and large objects on R2. We benefit from Cloudflare's DDoS protection, WAF, and physically secured data centers.
Encryption
- In transit. All traffic to and from the Service is encrypted with TLS.
- At rest. Data stored in our database and object storage is encrypted at rest by our infrastructure provider.
Authentication
Accounts and sessions are managed by Flowviant directly. We support OAuth sign-in with GitHub and Google, or a one-time code emailed to you — there are no passwords at all, so there is no password of yours for us to store, leak, or be phished for. Sessions are first-party cookies scoped to app.flowviant.com.
Payments
Paid plans aren't live yet. When they are, payments will be processed by Stripe, a PCI-DSS Level 1 certified provider, and Flowviant will never see or store full card numbers.
Access and permissions
Your code changes are pushed from your own machine by the Flowviant daemon — Flowviant holds no standing access to your repositories. The daemon acts under a project credential you can revoke at any time. Access is granted PER PROJECT: somebody you invite to one project cannot see or open another. Removing someone ends their open Terminal tabs and New task chats and revokes their session tokens; a machine they connected keeps serving the project until somebody disconnects it in Project settings › Machines.
AI data handling
Coding work runs on your own machine, under your own AI logins. Flowviant's servers run one model: the optional ship review quiz, which sends the change under review to Google Gemini when a quiz is made. Nothing else on our servers summarises or generates.
Backups and resilience
Our database supports point-in-time recovery, and our infrastructure is designed for high availability across Cloudflare's network.
Reporting a vulnerability
If you believe you've found a security issue, email security@flowviant.com with details and steps to reproduce. Please give us a reasonable opportunity to address it before any public disclosure. We will not pursue action against good-faith research that respects user privacy and avoids service disruption.
Subprocessors
The third parties that process data on our behalf are listed in our Privacy Policy.