BuildFlow

Security

Security posture, in plain English.

What we do, what we don't, and how to reach us when something matters.

Authentication

Short-lived JWT access tokens with refresh-rotation. Bcrypt with timing-safe compare for password hashing. CSRF tokens on every cookie-bearing endpoint. Sessions are revocable from the dashboard.

Data at rest

Postgres on encrypted disks. Per-row tenant scoping enforced at the application layer; row-level security policies enforced at the database layer for defense in depth.

Data in transit

TLS 1.3 everywhere. HSTS preloaded. Strict CSP. Cookies are httpOnly, Secure, SameSite=Lax. No mixed content; no third-party scripts on the marketing site.

Audit log

Every mutation — creates, edits, deletes, role changes, invitations, API key issuance — is written to an append-only log. Searchable, filterable, and exportable. Retention is configurable per workspace.

Soft-delete & restore

Default delete is soft. Restore is one click, until the configured retention window elapses. Hard-deletes are explicit, audited, and never silent.

Rate limiting

Per-IP and per-key rate limits on every public endpoint. Bucket-based with burst tolerance. 429 responses include a Retry-After header; abusive callers are auto-cooled.

Reporting a vulnerability

Email security@buildflow.io with details and a reproduction. We acknowledge within 24 hours, fix within 30 days for high-severity issues, and credit reporters who request it.

Questions? We answer security emails first.

Free forever for up to 5 members. Self-hostable. No credit card.