Trust
Trust
Security, privacy and reliability commitments in one place.
This section answers the questions a buyer asks before handing a company their business: what happens to the data, who else can see it, what the agent is allowed to do on its own, what we do when it breaks, and what we can prove rather than assert. It is written in plain language. The binding versions of the same commitments are in the legal documents.
The four things worth knowing first
- We name what we have not done. FlowFinds holds no SOC 2 report and no ISO 27001 certificate today. The security page says what we actually do instead, and where the gaps are.
- Your work is not training data. Storefront content, buyer orders and support email are not used to train models. See data handling and retention.
- The agent does not act unsupervised where the consequence is irreversible. It drafts organic campaigns and publishes none of them; it never moves money. Safety approach.
- The sub-processor list is short and real. Five vendors, each named with its role. Sub-processors.
Every page in this section
SecurityHow FlowFinds Solutions secures the platform and the data inside it.Data handling and retentionWhat we store, for how long, where it lives and who can reach it.Sub-processorsEvery third party that processes customer data on our behalf.Safety approachThe limits we put on agent authority, and why.Responsible disclosureHow to report a vulnerability, and what we commit to in return.Supported countriesWhere FlowFinds is available today.Availability commitmentOur incident policy, what is protected first, and how outages are reported.System statusCurrent state of every FlowFinds service, measured every five minutes, with the outage history.
Reporting something
A security vulnerability goes to [email protected] under the responsible disclosure policy, which states what we commit to in return. A privacy request goes to [email protected] and is handled under clause 9 of the privacy policy. Anything else reaches us through contact.