Security & trust
Agents that work for you, inside limits you set
Automation is only useful if you can hand it to your team without worrying about what it will do next. These are the controls that make that reasonable — each one shipped, not planned.
Workspace isolation
Every query is scoped to one workspace. It is a tested invariant, not a convention: a suite asserts that one workspace can never read another's projects, tasks, agents, workflows or audit records.
Agent boundaries (SOP)
Each agent carries a standard operating procedure: which tools it may use, when it must stop and ask a human, and what "done" means. It is enforced at the permission gate on every run, including unattended ones, and it can only narrow what the person running it is already allowed to do.
Per-tool permissions
Allow, ask-first, or off — per tool, per connector. Reads run silently; writes and deletions pause for a human yes unless you say otherwise.
Audit log
Who did what, when, and from where, recorded on an append-only table and scoped to your workspace. Exportable for review.
SSO and SCIM
Single sign-on for access, SCIM for provisioning and de-provisioning, so removing someone from your directory removes them here.
Access reviews and erasure
Scheduled access reviews to confirm who still needs what, and a data deletion route that removes a user's personal data on request.
On the roadmap, and not yet claimed
We keep SOC 2 control checklists internally and build against them, but we have not completed an external audit — so we do not describe ourselves as certified. Region-pinned data residency is not implemented either. If your procurement needs either, talk to us about timelines rather than taking a badge at face value.
Found something that looks wrong? Report it to security@flowversal.com and we will confirm receipt.