§ trust

Trust & Compliance

PromptFloe · Last updated June 26, 2026

Security and privacy underpin everything we build at PromptFloe. This page describes the documents we can share, the sub-processors that handle data on our behalf, and the practices that protect your work. We publish only what is true today and clearly mark what is in progress.

01 Documents

02 Security practices

Encryption

Data is encrypted in transit with TLS. Sensitive credentials such as OAuth tokens and webhook payloads are encrypted at rest with AES-256-GCM.

Access control

Workspace access is role-based (Owner / Admin / Member / Viewer). Internal service-to-service calls are authenticated with a shared secret using constant-time comparison.

Application security

We enforce CSRF protection, a strict Content-Security-Policy, HSTS, and rate limiting on authentication endpoints.

Monitoring

Errors and performance are monitored via Sentry and OpenTelemetry, and administrative actions are audit-logged.

Data residency

Primary application data is stored in India (AWS ap-south-1). LLM processing occurs in the US (Anthropic, OpenAI, and Google).

03 Sub-processors

We engage the third parties below to operate PromptFloe. We give customers under a DPA prior notice of material changes. To subscribe to change notices, email support@promptfloe.com.

Core infrastructure
Amazon Web Services (S3, CloudFront)Storage & CDNIndia (ap-south-1) + global
PostgreSQL (managed)Primary databaseIndia (ap-south-1)
Redis / DragonflyDBCache & queueSelf-hosted / cloud
RailwayApplication hostingUS
AI / LLM providers
AnthropicLLM generation (default)US
OpenAILLM generation & voiceUS
Google (Gemini)LLM generationUS
PineconeVector search / RAGUS (us-east-1)
Payments, email & comms
RazorpayPayments (India)India
StripePayments (international)US
ResendTransactional emailUS
Deepgram - opt-in (voice)Speech-to-textGlobal
Identity, analytics & monitoring
GitHub / Google (OAuth)Sign-inUS
SentryError monitoringUS/EU (configurable)
PostHogProduct analyticsUS/EU (configurable)
Deployment targets (customer-directed)
VercelApp hostingGlobal edge
NetlifyApp hostingGlobal

04 Contact

Privacy & data requests: support@promptfloe.com
Security & vulnerability reports: support@promptfloe.com
Grievance Officer (DPDP Act, 2023): named contact available on request.