Security

Built for teams that take data seriously

Customer conversations are sensitive. FlowsDesigner is built so that the people on your team see what they need to — and nothing more.

Encryption

Encryption at rest and in transit

  • TLS 1.2+ for every connection (web, API, WhatsApp Cloud API, calling)
  • AES-256 encryption at rest for the database
  • WhatsApp Cloud API tokens stored encrypted, never returned to the browser
  • Audio media on calls flows over TURN-TLS (port 443) — works through any firewall
Access control

Role-based access for every team member

  • Three roles: Admin, Manager, Agent — with permissions tuned to each
  • Agents only see what they need: inbox, contacts, their own scorecard
  • Phone masking for sensitive workflows (clinics, finance)
  • Two-factor authentication available for every account
  • Session timeout and forced sign-out controls for admins
AI

Transparent, opt-in AI

  • Bring your own AI key (BYOK) by default — pay OpenAI or Anthropic directly
  • Platform-managed AI is opt-in per workspace, gated by your admin
  • No customer conversations are used to train any model
  • Workspace-owner controls which features call AI
Data ownership

Your data stays yours

  • CSV export of contacts, conversations, deals — anytime, no lock-in
  • Webhook events for every conversation change so you can mirror to your warehouse
  • Configurable data retention windows
  • GDPR data-subject access + deletion requests honoured within 30 days

Security questions?

We're happy to walk through our architecture and answer specifics for procurement, compliance, or IT.