Professional-grade security
Your data security is our top priority. We implement industry-standard security measures to protect your business and your customers' information. Our application and database are hosted in Germany (EU) on Hetzner infrastructure; a few sub-processors, such as the AI assistant and payment processing, operate outside the EEA and are listed in our sub-processor register.
Data protection
Encryption at Rest
AES-256-GCMSession notes, client outcome records, integration credentials, payment tokens and two-factor secrets are encrypted with AES-256-GCM at the application layer before they reach the database. Customer contact fields such as name, primary email and primary phone are stored unencrypted so that search and message matching work.
Encryption in Transit
TLS 1.3All data transmitted between your browser and our servers is encrypted using TLS 1.3 with modern cipher suites.
Sign-in & Passwords
OAuth 2.0 · bcryptYou can sign in with Google, Facebook or Apple through OAuth 2.0, or with an email address and password. A password is never stored as you typed it — only a bcrypt hash of it, which cannot be turned back into the password.
JWT Token Security
RotatingAccess tokens expire after 1 hour. Refresh tokens are rotated on each use and can be revoked instantly.
Infrastructure Security
Hetzner ISO 27001Hosted on Hetzner in Germany. Hetzner data centres are ISO 27001 certified and provide enterprise-level physical security and DDoS mitigation at the network edge.
Database Backups
BackupsPostgreSQL is backed up nightly, and again before every production deployment and migration. Backups are encrypted with AES-256 — on the server and in off-site object storage — and kept for 30 days locally and 90 days off-site. Each week an automated drill downloads an off-site backup, decrypts it and restores it into a scratch database, so recovery is proven rather than assumed.
Security practices
Error Monitoring
Application errors and failed authentication attempts are logged and monitored via Sentry to detect anomalies early.
Regular Updates
Dependencies and systems are regularly updated to address security vulnerabilities and maintain best practices.
Access Controls
Per-user data isolation and role-based access control (RBAC) ensure team members only access data necessary for their role.
Internal Code Review
Code changes go through internal security review, with automated static analysis (Bandit) and Python dependency vulnerability scanning running as a gate on every push.
Compliance & data protection
GDPR-aligned
- Data processing agreements
- Right to access & deletion
- Data portability
- Breach notification
PCI DSS scope (via iyzico)
- Secure payment processing via iyzico
- No card data stored
- Tokenised transactions
- Fraud protection
Incident response
Our commitment
In the unlikely event of a security incident affecting your data, we commit to:
- Notifying affected users within 72 hours of discovery
- Providing clear information about what data was affected
- Taking immediate steps to contain and remediate the incident
- Conducting thorough post-incident reviews
Report a vulnerability
We appreciate responsible disclosure. If you discover a security vulnerability, please report it to us at contact@clientflow.center
We will acknowledge receipt within 24 hours and work with you to understand and address the issue promptly.