Your delivery data, under your control.
Flowstate reads what you connect and writes only what you approve. Here is exactly how that works, and where our compliance programme currently stands.
SOC 2 Type II
In progressIndependent audit of our security, availability and confidentiality controls over an observation window. Underway; we will publish the report when it completes.
GDPR
In progressData subject rights, lawful basis for processing, and a sub-processor register. Our processes are built to the regulation; the formal programme is being documented.
ISO 27001
PlannedAn information security management system certification. On the roadmap, not yet started — ask us for the current timeline.
CCPA
PlannedCalifornia Consumer Privacy Act rights and disclosure. Planned alongside the GDPR programme.
We publish the status rather than the badge. If your procurement process needs a certificate we do not hold yet, tell us early — we would rather have that conversation now than at contract stage.
How the product protects your data
Each of these is something we can show you in the running product, not a statement of intent.
Connections use OAuth, never passwords
Jira, Google and Microsoft are connected through their own consent screens. Flowstate never sees or stores a credential for those systems, and a connection can be revoked from either end at any time.
Nothing reaches your board unapproved
Every change Flowstate proposes for Jira waits in a sync queue until a person approves, edits or rejects it. Auto-sync is opt-in, configured per project, and its decisions stay visible in the same queue.
Workspace isolation
Every record — meetings, transcripts, insights, Jira data — is scoped to the workspace that owns it. Cross-workspace access is not an ACL to get wrong; the data is separated at the query.
Your meetings are not training data
Transcripts and the insights drawn from them are processed for your workspace and nothing else. Customer data is never used to train or fine-tune models, and never crosses between tenants.
Encrypted in transit and at rest
All traffic is TLS. Stored data — transcripts included — is encrypted at rest by the platform it sits on, which is itself operated under an independent audit.
The bot is a visible participant
The notetaker joins meetings as a named attendee that everyone in the call can see, and only the meetings you point it at. There is no silent recording, by design.
What your security team will ask
Answered plainly, including where the answer is “not yet”.
What data does Flowstate process?
Meeting transcripts from the calls you send the notetaker to, the Jira data your connection grants access to — projects, issues, sprints, users, project members — and the calendar entries needed to know which meetings to join. From those it derives blockers, decisions, action items and health signals.
Are our meetings used to train AI models?
No. Customer data is processed to produce your workspace's own insights and for nothing else. It is not used to train, fine-tune or evaluate models, and it is never shared between tenants.
Can Flowstate change our Jira board on its own?
Only where you have explicitly turned auto-sync on for that kind of suggestion. Everything else queues for a person. Each entry in the sync queue records who approved it and when, so a change can always be traced back to a decision.
How is data deleted?
Disconnecting an integration stops collection immediately. For deletion of stored data, write to privacy@flowstate.ai — the request routes to the team that can carry it out, and we will confirm when it is done.
Which sub-processors are involved?
Cloud hosting, AI inference and meeting transcription each involve a third party. The current list is available on request and is maintained as part of the GDPR programme above; we will tell you before it changes.
What we commit to
- Security questionnaires answered by the team that built the system
- Named contact for your InfoSec review, not a ticket queue
- Notice before any sub-processor changes
- Integration access revocable from your side at any time
- Data export on request, in a format you can actually read
- Disclosed vulnerabilities acknowledged and tracked to a fix
Ready for your security review?
We will walk your InfoSec team through the architecture, answer the questionnaire, and tell you straight where the compliance programme has got to.