Security & trust
Built for businesses that take their data seriously.
Flow Pilot holds your operational memory — client conversations, deal history, finance events. We treat that like the crown jewels it is.
Encryption
TLS 1.2+ in transit. AES-256 at rest across databases, backups and object storage. Secrets never touch the client.
GDPR-aligned
Data processed in the EU/UK. Data Processing Agreement available on request. Right to erasure and export honoured within 30 days.
Auth & RBAC
Google OAuth and secure passwords, session rotation, and a separate roles table with `has_role()` — no privilege claims on user profiles.
Audit logs
Every agent action, entitlement change and admin operation is logged with actor, timestamp and payload for forensics.
Row-level security
Every user-scoped table is protected by Postgres RLS. Data is invisible cross-tenant even to the backend.
Privacy-first
No selling of data, no third-party analytics on your business data, no LLM training on your memory.
Reliable infra
Edge-deployed on Cloudflare Workers. Managed Postgres with daily point-in-time backups (7-day retention).
Payments
Stripe-managed payments. Card numbers never touch Flow Pilot servers. Full VAT and tax handling by Stripe.
Sub-processors
- Supabase (Lovable Cloud) — Postgres, auth, storage · EU region
- Cloudflare Workers — application runtime · global edge
- Stripe — payments and tax · UK/EU
- Resend — transactional email · EU
Responsible disclosure
Found a vulnerability? Report it to security@flow-pilot.co.uk. We acknowledge within 24 hours and never pursue legal action against good-faith researchers.