Security
Security at FLOWOFKANBAN
Enterprise-grade security for your operations, data, and workflows. Last reviewed: August 2026.
Our Security Commitment
FLOWOFKANBAN is built with a security-first mindset from the ground up. We design our platform using modern cloud infrastructure, strong encryption, and industry-standard controls — so you can focus on running your material flow, not worrying about your data.
- Secure-by-design architecture — security is embedded in every layer, not bolted on after.
- Continuous monitoring and improvement — we actively scan, test, and refine our security posture.
- Alignment with enterprise security expectations — we meet the bar that IT and security teams require.
- Transparent communication and responsible disclosure — we are open about how we handle security issues.
Data Protection & Encryption
Encryption controls are inherited from our underlying cloud platform (Base44 / Wix Cloud). FLOWOFKANBAN enforces additional application-layer protections on top.
- TLS 1.2+ enforced on all connections, with HSTS enabled.
- Encryption at rest for all stored customer data, with encrypted platform-managed backups.
- No plaintext secrets or API keys exposed in client-side code.
- Service-role operations restricted to verified privileged users; all sensitive operations (billing, tenant management) require server-side authentication.
Application & Infrastructure Security
FLOWOFKANBAN is hosted on the Base44 / Wix Cloud platform, and our development practices align with modern secure software development lifecycle (SDLC) standards.
- Role-based access control (RBAC) enforced at the database and API layer — users only see what they are permitted to see.
- Multi-tenant data isolation enforced at the query level — tenant scoping prevents data from crossing account boundaries.
- Protection against XSS, CSRF, clickjacking, injection, and other OWASP Top 10 attack vectors.
- Backend functions run in a serverless edge environment with no persistent server exposure.
- Database access is mediated exclusively through the Base44 SDK — no direct database connections from the client.
- All privileged API endpoints require authentication and enforce role-based authorization.
Identity & Access Management
Authentication is managed by the Base44 platform. FLOWOFKANBAN enforces role-based authorization on top of the platform's identity layer.
- User authentication, password handling, and session management provided by the Base44 platform — secure token handling and automatic session expiration.
- Role-based access control with five roles: Tenant Admin, Board Owner, Team Lead, Contributor, and Viewer — each with differentiated entity-level permissions.
- Row-level security (RLS) enforced on every entity — users can only read, create, update, or delete records within their own tenant.
- Privileged backend functions verify user role via JWT and database lookup before executing sensitive operations.
- Multi-factor authentication (MFA) and SSO / SAML integration are on the product roadmap for enterprise customers.
Compliance & Governance
We are actively building the operational foundation for formal compliance certifications.
- SOC 2 Type II readiness currently underway — controls are being implemented and documented.
- Vendor risk documentation and security questionnaires available upon request.
- Customers may request deletion of their data in compliance with applicable privacy regulations.
- Subprocessor transparency — we maintain a current list of third-party services that process customer data.
Data Retention & Deletion
When a tenant cancels their subscription, all data remains accessible until the end of the current billing period. Tenants may request permanent deletion of all their data — including loops, cards, locations, and move history — at any time by contacting our support team. Deletion is performed upon verified request and is irreversible.
Responsible Disclosure
We appreciate the work of security researchers and the broader security community. If you believe you have discovered a vulnerability in FLOWOFKANBAN, we ask that you disclose it to us responsibly so we can investigate and remediate it promptly — without putting our customers at risk.
- Please provide sufficient detail to reproduce the issue, including steps, affected endpoints, and potential impact.
- We aim to acknowledge your report within 3 business days and will keep you informed as we investigate.
- We will not pursue legal action against researchers acting in good faith under this policy.
- Please do not access, modify, or exfiltrate customer data during testing.
Report a vulnerability: securityflowofkanban@oandpadvisoryservices.com
Subprocessors
FLOWOFKANBAN uses a small number of trusted third-party services to deliver the platform. This list is reviewed and updated regularly. Last updated: August 2026.
| Subprocessor | Purpose | Location |
|---|---|---|
| Base44 / Wix Cloud | Application hosting, database, and runtime infrastructure | United States |
| Stripe | Payment processing and subscription billing | United States |
| Google Fonts | Web typography (Inter font family) | United States |
Contact & Support
Have a security question, concern, or request? We're here to help.
Security Team
securityflowofkanban@oandpadvisoryservices.comVulnerability reports, security questions, compliance inquiries.
General Support
supportflowofkanban@oandpadvisoryservices.comAccount issues, product questions, and general help.
