Security
Built for teams that take data seriously
Customer conversations are sensitive. FlowsDesigner is built so that the people on your team see what they need to — and nothing more.
Encryption
Encryption at rest and in transit
- TLS 1.2+ for every connection (web, API, WhatsApp Cloud API, calling)
- AES-256 encryption at rest for the database
- WhatsApp Cloud API tokens stored encrypted, never returned to the browser
- Audio media on calls flows over TURN-TLS (port 443) — works through any firewall
Access control
Role-based access for every team member
- Three roles: Admin, Manager, Agent — with permissions tuned to each
- Agents only see what they need: inbox, contacts, their own scorecard
- Phone masking for sensitive workflows (clinics, finance)
- Two-factor authentication available for every account
- Session timeout and forced sign-out controls for admins
AI
Transparent, opt-in AI
- Bring your own AI key (BYOK) by default — pay OpenAI or Anthropic directly
- Platform-managed AI is opt-in per workspace, gated by your admin
- No customer conversations are used to train any model
- Workspace-owner controls which features call AI
Data ownership
Your data stays yours
- CSV export of contacts, conversations, deals — anytime, no lock-in
- Webhook events for every conversation change so you can mirror to your warehouse
- Configurable data retention windows
- GDPR data-subject access + deletion requests honoured within 30 days
Security questions?
We're happy to walk through our architecture and answer specifics for procurement, compliance, or IT.