Enterprise

One standard,
in every
application.

Every FlowZa AI application is built to the same security and operational bar, and enforces it inside its own boundary. That is deliberately useful in procurement: the review you run on the first application tells you what to expect of the next, and a finding in one cannot reach another. These are the controls, stated plainly enough to hand to a security reviewer.

Access

Who can see what

  • Single sign-on

    SAML 2.0 and OIDC against any compliant issuer, including Entra ID, Okta and Google Workspace. Local passwords can be disabled entirely at the tenant level.

  • Directory-driven lifecycle

    SCIM provisioning creates, updates and deactivates accounts from your directory. A departure in HR removes platform access in the same operation.

  • Role-based, attribute-aware

    Permissions combine role with attributes such as entity, region and cost centre, evaluated at query time. A user cannot retrieve a record they are not entitled to, through the UI or the API.

  • Agents inherit, never exceed

    An AI agent runs with the delegated identity of the person or service that invoked it. It cannot read or write anything that principal could not.

  • Session control

    Configurable idle and absolute timeouts, device and IP conditions, and administrative session revocation that takes effect immediately.

  • Break-glass, recorded

    Elevated access requires a documented reason, notifies a second administrator, and expires automatically.

Data

Where it lives and how it is protected

  • Encryption

    TLS 1.3 in transit. AES-256 at rest with per-tenant key separation and scheduled rotation. Customer-managed keys are available on enterprise agreements.

  • Residency

    The storage region is selected at provisioning and does not change without an explicit, logged migration. Backups and replicas stay within the selected jurisdiction.

  • Isolation

    Within each application, tenant identity is enforced beneath the application code, at the point the query runs — so a query cannot cross a tenant boundary even if the application logic is wrong.

  • Retention and deletion

    Configurable retention per object class, legal hold, and verified deletion on termination with a certificate issued on completion.

  • Backups

    Continuous point-in-time recovery with cross-region copies. Restores are exercised on a schedule rather than assumed to work.

  • Sub-processors

    A current list is published with the purpose and region of each, and material changes are notified in advance of taking effect.

Assurance

Certification status

Stated as of the date below and updated as each programme completes. Reports and questionnaires are available under NDA through your account team.

Certification and assurance programme status
ProgrammeStatus
SOC 2 Type IIAudit window in progress
ISO/IEC 27001Implementation underway
GDPR — controller and processorDPA available
Penetration testingAnnual, third party; summary on request
Vulnerability disclosurePublished policy, monitored channel

Status shown for illustration in this build and should be confirmed against the current assurance register before publication.

Operations

Running it

99.9%Monthly availability target, measured at the API edge
<15mRecovery point objective for the primary datastore
<4hRecovery time objective for a full regional failover
24×7Named escalation path on enterprise agreements
  • Change management

    Releases ship behind flags with staged rollout and automatic rollback on error-budget burn. Tenants on enterprise agreements can pin a release window.

  • Status and incidents

    Live status page with component-level history, and post-incident reviews published for anything customer-affecting.