Encryption everywhere
TLS in transit and AES-256 encryption at rest through our infrastructure providers for stored documents and databases. Signed PDFs live in access-controlled object storage.
FlowSign is designed so that the important documents you send and sign are secure in transit, secure at rest, and defensible under New Zealand privacy law. This page is the one-stop for procurement, IT and compliance reviews.
TLS in transit and AES-256 encryption at rest through our infrastructure providers for stored documents and databases. Signed PDFs live in access-controlled object storage.
Principle of least privilege for staff. Administrative access is via Google Workspace single sign-on with mandatory two-factor authentication.
Every customer-scoped database query is filtered by organisation identifier so one customer's documents and audit trail cannot be returned to another. Object storage is protected by scoped, short-lived signed URLs.
Every security-relevant action is recorded and retained for the life of the associated document. Purge redacts identifiers but keeps the event.
Our contractual and privacy commitments are published and versioned. Read them in full:
Our Privacy Officer is Anna Woodward - reach her at privacy@flowsign.app. Business customers can request a signed Data Processing Addendum by emailing legal@flowsign.app.
We take security posture seriously and are open about where we're headed. Items we are actively working towards:
If a certification or specific control is important to your procurement process, we are happy to walk you through where we stand. Email legal@flowsign.app.
Email security@flowsign.app with a description of the issue and steps to reproduce. We aim to acknowledge reports within one business day, keep you updated as we investigate, and credit you (if you would like credit) once the issue is resolved. Please give us a reasonable time to fix an issue before publishing it.