Why this page exists

Pre-launch status. These notes describe implemented safeguards and remaining checks; they are not a security certification.

Credentials in a blueprint

Input is received by the server. Recognized secrets in supported fields and patterns are masked before diagnostic analysis. This does not guarantee that every secret or personal identifier is detected. Remove sensitive data before uploading.

In transit and at rest

Production configuration requires HTTPS. Hosted TLS, database access, backup protection and operational settings remain to be verified on the deployed environment.

How long it is kept

Analyses are stored for history. A plan-based viewing window is separate from physical deletion. Production retention and backup schedules must be finalized before opening the service.

Who can see it

Application permissions separate personal analyses and shared team spaces. Shared spaces use owner, editor and viewer roles. Authorized team members can access their team’s shared spaces. Operational administrator access still requires a documented policy.

Sub-processors

The same list as in the privacy notice, kept in one place so it cannot drift apart.

Reporting a vulnerability

Report suspected vulnerabilities privately to FlowFix.contact.support@gmail.com. Do not include passwords or live tokens. No guaranteed response time is currently offered.