Security First

Professional-grade security

Your data security is our top priority. We implement industry-standard security measures to protect your business and your customers' information. Our application and database are hosted in Germany (EU) on Hetzner infrastructure; a few sub-processors, such as the AI assistant and payment processing, operate outside the EEA and are listed in our sub-processor register.

Active
Monitoring
<72h
Breach Notification
TLS 1.3
Transport Encryption
GDPR
Compliance

Data protection

Encryption at Rest

AES-256-GCM

Session notes, client outcome records, integration credentials, payment tokens and two-factor secrets are encrypted with AES-256-GCM at the application layer before they reach the database. Customer contact fields such as name, primary email and primary phone are stored unencrypted so that search and message matching work.

Encryption in Transit

TLS 1.3

All data transmitted between your browser and our servers is encrypted using TLS 1.3 with modern cipher suites.

Sign-in & Passwords

OAuth 2.0 · bcrypt

You can sign in with Google, Facebook or Apple through OAuth 2.0, or with an email address and password. A password is never stored as you typed it — only a bcrypt hash of it, which cannot be turned back into the password.

JWT Token Security

Rotating

Access tokens expire after 1 hour. Refresh tokens are rotated on each use and can be revoked instantly.

Infrastructure Security

Hetzner ISO 27001

Hosted on Hetzner in Germany. Hetzner data centres are ISO 27001 certified and provide enterprise-level physical security and DDoS mitigation at the network edge.

Database Backups

Backups

PostgreSQL is backed up nightly, and again before every production deployment and migration. Backups are encrypted with AES-256 — on the server and in off-site object storage — and kept for 30 days locally and 90 days off-site. Each week an automated drill downloads an off-site backup, decrypts it and restores it into a scratch database, so recovery is proven rather than assumed.

Security practices

Error Monitoring

Application errors and failed authentication attempts are logged and monitored via Sentry to detect anomalies early.

Regular Updates

Dependencies and systems are regularly updated to address security vulnerabilities and maintain best practices.

Access Controls

Per-user data isolation and role-based access control (RBAC) ensure team members only access data necessary for their role.

Internal Code Review

Code changes go through internal security review, with automated static analysis (Bandit) and Python dependency vulnerability scanning running as a gate on every push.

Compliance & data protection

GDPR-aligned

  • Data processing agreements
  • Right to access & deletion
  • Data portability
  • Breach notification

PCI DSS scope (via iyzico)

  • Secure payment processing via iyzico
  • No card data stored
  • Tokenised transactions
  • Fraud protection

Incident response

Our commitment

In the unlikely event of a security incident affecting your data, we commit to:

  • Notifying affected users within 72 hours of discovery
  • Providing clear information about what data was affected
  • Taking immediate steps to contain and remediate the incident
  • Conducting thorough post-incident reviews

Report a vulnerability

We appreciate responsible disclosure. If you discover a security vulnerability, please report it to us at contact@clientflow.center

We will acknowledge receipt within 24 hours and work with you to understand and address the issue promptly.

Related documents