Security Architecture

Built for Uncompromising Security

How Flow protects your social channels, API tokens, content queues, and brand assets with defense-in-depth engineering.

At Rest & In Transit

AES-256 & TLS 1.3 Encryption

All social media tokens, scheduled queues, and user assets are encrypted at rest using AES-256-GCM. All communications use TLS 1.3.

Zero Password Storage

OAuth 2.0 PKCE Token Vault

We authenticate with X, Meta, LinkedIn, TikTok, and YouTube strictly through OAuth 2.0 with PKCE. We never request or store user passwords.

Kernel-Level Isolation

Supabase Multi-Tenant RLS

Strict Row Level Security (RLS) policies are enforced at the database kernel level. Users and teams can only query their isolated records.

Zero Model Training

BYOK Zero-Retention AI Pipeline

When you provide your own API keys for OpenAI, Anthropic, or Google DeepMind, prompts are never logged, cached, or trained upon.

Defense-in-Depth Engineering Layers

1. Real-Time Token Isolation

Platform refresh tokens are encrypted using unique user keys before storage. When a post is dispatched, the token is momentarily decrypted in volatile memory for the outbound HTTP request and discarded immediately afterward.

2. Multi-Factor & Single Sign-On (SSO)

Flow supports Google OAuth, GitHub OAuth, and passwordless magic links. Team and Enterprise accounts can integrate with SAML 2.0 SSO and enforce mandatory MFA for all team workspace members.

3. Continuous Penetration Testing & Vulnerability Audits

We partner with independent security research firms to perform continuous automated dynamic application security testing (DAST) and periodic third-party penetration audits.

4. Responsible Disclosure Program

Security researchers who discover potential vulnerabilities are invited to report findings to security@flow.app. We acknowledge all legitimate reports within 12 hours.

Enterprise-grade security, zero complexity

Start your 7-day free trial today. No credit card required.

Start 7-Day Free Trial