Built for Uncompromising Security
How Flow protects your social channels, API tokens, content queues, and brand assets with defense-in-depth engineering.
AES-256 & TLS 1.3 Encryption
All social media tokens, scheduled queues, and user assets are encrypted at rest using AES-256-GCM. All communications use TLS 1.3.
OAuth 2.0 PKCE Token Vault
We authenticate with X, Meta, LinkedIn, TikTok, and YouTube strictly through OAuth 2.0 with PKCE. We never request or store user passwords.
Supabase Multi-Tenant RLS
Strict Row Level Security (RLS) policies are enforced at the database kernel level. Users and teams can only query their isolated records.
BYOK Zero-Retention AI Pipeline
When you provide your own API keys for OpenAI, Anthropic, or Google DeepMind, prompts are never logged, cached, or trained upon.
Defense-in-Depth Engineering Layers
1. Real-Time Token Isolation
Platform refresh tokens are encrypted using unique user keys before storage. When a post is dispatched, the token is momentarily decrypted in volatile memory for the outbound HTTP request and discarded immediately afterward.
2. Multi-Factor & Single Sign-On (SSO)
Flow supports Google OAuth, GitHub OAuth, and passwordless magic links. Team and Enterprise accounts can integrate with SAML 2.0 SSO and enforce mandatory MFA for all team workspace members.
3. Continuous Penetration Testing & Vulnerability Audits
We partner with independent security research firms to perform continuous automated dynamic application security testing (DAST) and periodic third-party penetration audits.
4. Responsible Disclosure Program
Security researchers who discover potential vulnerabilities are invited to report findings to security@flow.app. We acknowledge all legitimate reports within 12 hours.
Enterprise-grade security, zero complexity
Start your 7-day free trial today. No credit card required.