FlowTriage

Security & Trust

Last updated: September 2, 2026

1. Our approach

FlowTriage handles your customers' conversations, so we treat every message, contact and document as confidential by default. This page describes, in plain language, the controls actually built into the platform — not aspirations.

2. Data protection & POPIA

FlowTriage is operated from South Africa and built for POPIA, with GDPR-aligned practices for international customers. We store only what the platform needs to operate, we act as an operator processing personal information on your instructions, and we never sell or share customer data with third parties for their own purposes. Automated outreach honours a per-contact do-not-contact flag that is enforced in the sending machinery itself — flagged contacts are excluded before any automated message is created, and un-flagging always requires a human decision.

3. Encryption

All traffic between your browser, our APIs, the mobile app and FlowTriage is encrypted in transit with TLS. Sensitive credentials your workspace stores with us — WhatsApp access tokens, connector API keys, integration secrets — are additionally encrypted at the application layer before they reach the database, so they are never held in plain text.

4. Workspace isolation

Every FlowTriage workspace is strictly isolated. Each record — conversations, tickets, contacts, bookings, templates, tags, files — belongs to exactly one workspace, and every query is scoped to it. Cross-workspace requests return "not found" rather than "forbidden", so the existence of another workspace's data is never confirmed. Inbound webhooks carry their own tenant guards: WhatsApp events are dropped unless the receiving business account matches the workspace, and store webhooks are verified by cryptographic signature.

5. Access control

Workspace access is role-based (admin, manager, staff, third-party), with sensitive settings and reports restricted to admins and managers. API access uses scoped tokens with explicit abilities — a token minted for product search cannot touch tickets, and service-account tokens for integrations are limited to exactly the surfaces they need.

6. AI safety

FlowTriage's AI answers only from your own data — your knowledge base, your product index, your team's own sent replies — and every automated send is recorded with an audit trail. Auto-sent replies land in a review queue where your team can approve or flag them, and the AI's standing guidance changes only when a human approves a proposed rule. Connector calls from the AI pass through a security gateway with a tool allow-list, an audit log, response size caps and credential redaction; outbound connector URLs are validated so requests can never reach private or internal networks.

7. Payments

FlowTriage never sees or stores card numbers. Payment links are created and settled by your own payment provider (such as Yoco); we store only the reference and status your provider reports back.

8. Questions

For security questions, disclosure of a suspected vulnerability, or a copy of our data-processing terms, contact privacy@flowtriage.com. We respond to security reports as a priority.