§ security

Security you can verify.

PromptFloe is built and operated with security at its core. We protect your account, your code, and your data with encryption, least-privilege access, and a verified-build security gate - and we say plainly where we are on the compliance roadmap.

§ how we protect your data

Encryption in transit & at rest

All traffic runs over TLS. Data at rest is encrypted by our managed providers (AWS, Supabase/Postgres). Secrets live in platform secret stores, never in source.

Row-level security by default

Generated full-stack apps ship with Supabase Row-Level Security - every request is scoped to the authenticated user. Request-time CRUD goes through the user JWT, never a superuser key.

Authentication & access

Cookie-based refresh tokens (httpOnly), OAuth sign-in (GitHub / Google), and least-privilege access to production systems. Enterprise SSO / RBAC is available on Enterprise plans.

Data residency

Production application data is hosted in India (AWS ap-south-1). LLM processing runs in the US. No DPA-account data is routed to China-based models.

Verified-build security gate

Generated code passes a security review gate in the build pipeline before you ship - surfacing common issues (exposed secrets, unsafe queries, missing auth) early.

Sub-processors & DPA

We maintain a public sub-processor register and counter-sign DPAs (GDPR Art. 28 / DPDP) on request. Full detail lives in the Trust center.

§ responsible disclosure

Found a vulnerability? Tell us.

We welcome reports from security researchers and take every one seriously. If you believe you have found a security issue in PromptFloe or a generated app, please email us directly with enough detail to reproduce it. We will acknowledge your report and keep you updated as we investigate.

  • • Email security@promptfloe.com with steps to reproduce, impact, and any proof-of-concept.
  • • Please give us reasonable time to investigate and remediate before public disclosure.
  • • Do not access, modify, or delete data that is not your own, and avoid degrading service for others.
  • • Act in good faith, and we will treat your report in good faith.
Report a vulnerability →
Security contact

security@promptfloe.com

For DPAs, security questionnaires, and sub-processor detail, see the Trust center.

Compliance & documents

Sub-processor register, DPA, TIA, and our compliance roadmap (SOC 2 in progress, ISO 27001 planned) live in the Trust center.

Trust & Compliance
Where we are

We describe only what is true today. PromptFloe does not yet hold a SOC 2 or ISO 27001 certification - a SOC 2 engagement is underway and ISO 27001 is planned on the same control base. We will update this page and the Trust center as those reports are issued.