Security

Security at FLOWOF1

Enterprise‑grade security for your operations, data, and workflows.

Last reviewed: July 2026

TLS 1.2+ Encryption
RBAC Enforced
Tenant Data Isolation
SOC 2 Readiness Underway

Our Security Commitment

FLOWOF1 is built with a security‑first mindset from the ground up. We design our platform using modern cloud infrastructure, strong encryption, and industry‑standard controls — so you can focus on running your operations, not worrying about your data.

  • Secure-by-design architecture — security is embedded in every layer, not bolted on after.
  • Continuous monitoring and improvement — we actively scan, test, and refine our security posture.
  • Alignment with enterprise security expectations — we meet the bar that IT and security teams require.
  • Transparent communication and responsible disclosure — we are open about how we handle security issues.

Data Protection & Encryption

Encryption controls are inherited from our underlying cloud platform (Base44 / Wix Cloud). FLOWOF1 enforces additional application-layer protections on top.

Platform-Inherited (Base44 / Wix Cloud)

  • TLS 1.2+ enforced on all connections
  • HSTS enabled with long-duration max-age
  • Encryption at rest for all stored customer data
  • Encrypted backups managed by the platform

FLOWOF1 Application Layer

  • Enterprise-grade HTTP security headers on all API responses: HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, Cross-Origin policies
  • No plaintext secrets or API keys exposed in client-side code
  • Service-role operations restricted to verified admin users
  • All sensitive operations (billing, tenant management) require server-side authentication

Application Security

Our development and deployment practices are aligned with modern secure software development lifecycle (SDLC) standards.

  • Role-based access control (RBAC) enforced at the database and API layer — users only see what they are permitted to see.
  • Multi-tenant data isolation enforced at the query level — tenant_id scoping prevents data from crossing account boundaries.
  • Enterprise-grade HTTP security headers deployed on all API responses: HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy, Cross-Origin policies.
  • Protection against XSS, CSRF, clickjacking, injection, and other OWASP Top 10 attack vectors.
  • Authentication and session management handled by the Base44 platform — secure token handling and automatic session expiration.
  • Admin-only backend functions verify user role via JWT and database lookup before executing privileged operations.

Infrastructure Security

FLOWOF1 is hosted on the Base44 / Wix Cloud platform, which provides the underlying infrastructure, runtime, and database services.

  • Hosted on Base44 / Wix Cloud infrastructure with enterprise-grade cloud providers.
  • Application runtime and database services managed and maintained by the platform.
  • Backend functions run in a serverless edge environment with no persistent server exposure.
  • Database access is mediated exclusively through the Base44 SDK — no direct database connections from the client.
  • All API endpoints require authentication and enforce role-based authorization.

Identity & Access Management

Authentication is managed by the Base44 platform. FLOWOF1 enforces role-based authorization on top of the platform's identity layer.

  • User authentication, password handling, and session management provided by the Base44 platform.
  • Multi-factor authentication (MFA) — on the near-term product roadmap.
  • SSO / SAML integration planned for enterprise customers.
  • Role-based access control with four roles: platform_admin, admin, scheduler, and operator — each with differentiated entity-level permissions.
  • Row-level security (RLS) enforced on every entity — users can only read, create, update, or delete records within their own tenant.
  • Admin-only backend functions require platform_admin role, verified via JWT and database lookup.

Compliance & Governance

We are actively building the operational foundation for formal compliance certifications.

  • SOC 2 Type II readiness currently underway — controls are being implemented and documented.
  • Vendor risk documentation and security questionnaires available upon request.
  • Customers may request deletion of their data in compliance with applicable privacy regulations.
  • Subprocessor transparency — we maintain a current list of third-party services that process customer data.

Data Retention & Deletion

When a tenant cancels their subscription, all data remains accessible until the end of the current billing period. Tenants may request permanent deletion of all their data — including jobs, schedules, workcenters, and scenarios — at any time by contacting our support team. Deletion is performed manually by our team upon verified request and is irreversible.

Responsible Disclosure

We appreciate the work of security researchers and the broader security community. If you believe you have discovered a vulnerability in FLOWOF1, we ask that you disclose it to us responsibly so we can investigate and remediate it promptly — without putting our customers at risk.

  • Please provide sufficient detail to reproduce the issue, including steps, affected endpoints, and potential impact.
  • We aim to acknowledge your report within 3 business days.
  • We will keep you informed as we investigate and remediate confirmed findings.
  • We will not pursue legal action against researchers acting in good faith under this policy.
  • Please do not access, modify, or exfiltrate customer data during testing.

Subprocessors

FLOWOF1 uses a small number of trusted third-party services to deliver the platform. We maintain this list transparently.

SubprocessorPurposeLocation
Base44 / Wix CloudApplication hosting, database, and runtime infrastructureUnited States
StripePayment processing and subscription billingUnited States
ResendTransactional email deliveryUnited States
Google FontsWeb typography (Inter font family)United States

This list is reviewed and updated regularly. Last updated: July 2026.

Contact & Support

Have a security question, concern, or request? We're here to help.

Security Team

securityflowof1@oandpadvisoryservices.com

Vulnerability reports, security questions, compliance inquiries.

General Support

supportflowof1@oandpadvisoryservices.com

Account issues, product questions, and general help.