Trust center

Security is part of the architecture

Flowtix uses server-side authorization and organization-scoped database policies. External carrier, AI, and storage providers must be reviewed and configured separately before production use.

Security controls

Supabase SSR authentication

Sessions are resolved server-side using secure cookie-based authentication patterns.

Row Level Security

PostgreSQL policies scope supported application data to authorized organization members.

Role-based authorization

Workspace roles and server-side checks limit sensitive administrative operations.

Secret management

Private credentials belong in server-side environment variables and are not committed to source control.

Data minimization

Only collect and retain information necessary for legitimate product and customer workflows.

Responsible disclosure

Report suspected vulnerabilities through the contact page without including active secrets or unnecessary personal data.