Current controls, not an independent certification
Security overview
How StudioFlow protects accounts, workspaces, integrations and payments, including current limitations.
Last updated 21 August 2026
Security controls
- Signed, HTTP-only sessions and password hashing protect user authentication; two-factor authentication is available.
- Role and plan checks restrict product functions. Workspace identifiers are used by server-side application queries to separate customer records.
- Selected integration secrets can use application-level AES-256-GCM encryption when the production encryption key is configured.
- Supported payment and inbound webhook messages are signature-checked before trusted state changes.
- Security headers and HTTPS are applied by the application and hosting layer. Remote email images are blocked by default.
Limits of this statement
- StudioFlow does not claim SOC 2, ISO 27001, PCI DSS or another independent certification.
- Workspace separation is primarily enforced in application queries, not represented as PostgreSQL row-level security.
- Audit coverage varies by feature. We do not claim every action is logged.
- Storage, encryption, monitoring and backup protections depend on the verified production configuration.
- No uptime, recovery-time or recovery-point commitment applies unless stated in a signed enterprise order.
Shared responsibility
Customers must assign appropriate roles, protect accounts, remove departed users, secure connected mailboxes and integrations, and ensure they have lawful authority to place personal data in StudioFlow.
Questions about this document may be sent to hello@studioflow.business. Draft contractual and privacy materials require formal approval before reliance.