Security engineered to the standard of the systems it protects
From encryption to access control to independent audits, SystemFlow is built so the teams auditors trust can trust us too.
Defense in depth
Encryption
TLS in transit and encrypted storage at rest through our infrastructure providers.
Access control
Role-based access control and enforced least privilege for every account.
Activity logging
State-changing actions are logged with the acting user, so account activity is traceable.
Isolation
Per-account data isolation at the database layer. Self-hosting is on the roadmap, not shipped yet.
Vulnerability management
Dependencies are kept current and security-relevant reports are welcome at security@gigplux.com - we do not yet run a formal bounty program.
Incident response
A small team means a short chain of command. If something breaks, you will hear from a real person, fast.
Honest about where we are
SystemFlow is in beta and we have not completed third-party audits yet. These are the frameworks we design against and plan to certify as the company grows.
Need to complete a security review?
Our team will work through your questionnaire and provide the documentation you need.