Security

Limit access. Keep records small. Fail closed.

AgencyFlow is designed to store installation records and summary counts without collecting the customer records that its current feature does not need.

Report a security concern →

Protection at each part of the request path.

These controls describe the deployed development environment. We update this page when material data flows or safeguards change.

01

HTTPS only

Website, installation, callback, webhook, and application traffic use encrypted HTTPS connections.

02

Managed encryption

OAuth tokens, queues, database records, notifications, and secret values use AWS-managed encryption at rest.

03

Restricted credentials

OAuth secrets stay in Secrets Manager. Application roles can read only the specific secret or service resource required for their job.

04

Short-lived sessions

The embedded dashboard exchanges signed context for a five-minute session kept in page memory rather than browser storage.

05

Verified events

Webhook authenticity is checked before processing. Duplicate events are rejected, and downstream work runs through a bounded queue.

06

Redacted logs

Logs exclude access tokens, refresh tokens, authorization codes, authentication headers, full webhook bodies, and application-form contents.

The current scan stores counts, not customer records.

AgencyFlow stores platform identifiers, installation status, token expiration, granted permissions, scan status, and totals for workflows, calendars, custom fields, and custom values.

The current feature does not request contacts, conversations, messages, appointments, opportunities, field values, or full workflow definitions.

Read the full Privacy Policy →

Infrastructure with a defined role.

Amazon Web Services hosts the API, functions, database, queues, secret storage, operational logs, and pilot-application notification. Cloudflare provides website delivery, DNS, TLS, and network security.

Send enough detail to reproduce the issue, never live credentials.

Email [email protected] with the affected URL, observed behavior, time, and safe reproduction steps.

Do not include passwords, authorization codes, access tokens, refresh tokens, API keys, customer records, or active exploit traffic. We will acknowledge a credible report as soon as practical and coordinate testing before public disclosure.

Security contact

Found something we should investigate?

Send a report ↗