Security
Security posture, in plain English.
What we do, what we don't, and how to reach us when something matters.
Authentication
Short-lived JWT access tokens with refresh-rotation. Bcrypt with timing-safe compare for password hashing. CSRF tokens on every cookie-bearing endpoint. Sessions are revocable from the dashboard.
Data at rest
Postgres on encrypted disks. Per-row tenant scoping enforced at the application layer; row-level security policies enforced at the database layer for defense in depth.
Data in transit
TLS 1.3 everywhere. HSTS preloaded. Strict CSP. Cookies are httpOnly, Secure, SameSite=Lax. No mixed content; no third-party scripts on the marketing site.
Audit log
Every mutation — creates, edits, deletes, role changes, invitations, API key issuance — is written to an append-only log. Searchable, filterable, and exportable. Retention is configurable per workspace.
Soft-delete & restore
Default delete is soft. Restore is one click, until the configured retention window elapses. Hard-deletes are explicit, audited, and never silent.
Rate limiting
Per-IP and per-key rate limits on every public endpoint. Bucket-based with burst tolerance. 429 responses include a Retry-After header; abusive callers are auto-cooled.
Reporting a vulnerability
Email security@buildflow.io with details and a reproduction. We acknowledge within 24 hours, fix within 30 days for high-severity issues, and credit reporters who request it.
Questions? We answer security emails first.
Free forever for up to 5 members. Self-hostable. No credit card.