FlowDule
Trust Center

Security and Access Control in FlowDule

This section describes the security mechanisms that protect data across chains, locations, and roles - from encryption and multi-tenancy to logging and multi-factor authentication for privileged access.

Security and Access Control in FlowDule (AI-genereret billede)AI-genereret indhold

Security is part of the architecture, not an add-on

FlowDule is built with multi-tenancy from day one, where chains, locations, and users are separated. Security is not an extra layer - it's integral to how data is stored, accessed, and logged.

This page describes the key mechanisms in outline. The binding security level follows from the accepted Data Processing Agreement, the customer annex and the version-bound TOMs annex, and the Security description gives the overall picture.

Security

The key security layers in the platform

Encryption, isolation, access, and traceability

Encryption at rest and in transit (AI-genereret billede)EncryptionAI-genereret indhold

Encryption at rest and in transit

Communication with FlowDule is protected by modern transport encryption, and the approved production baseline uses encryption at rest for relevant databases, files and sensitive fields.

Data separation between chains and locations (AI-genereret billede)IsolationAI-genereret indhold

Data separation between chains and locations

Data per company and location is kept separate, as the platform is designed to prevent access to data across different organizations or departments.

Personal accounts and multi-factor authentication for privileged access (AI-genereret billede)AccessAI-genereret indhold

Personal accounts and multi-factor authentication for privileged access

The security model requires personal accounts rather than shared credentials, together with multi-factor authentication for privileged and internal production access.

Role and permission management (AI-genereret billede)ControlAI-genereret indhold

Role and permission management

Determine who can view, edit, or manage which data, ensuring only authorized users access sensitive information.

Consent and PII protection on export (AI-genereret billede)GDPRAI-genereret indhold

Consent and PII protection on export

FlowDule logs consent upon creation, and personally identifiable information can be masked upon export when relevant.

Audit logs and backup (AI-genereret billede)TraceabilityAI-genereret indhold

Audit logs and backup

Relevant actions on client and journal data must be traceable to an identified user or system component, and backup and restore mechanisms are used and must be tested in an isolated environment.

Isolation

Multi-tenancy as the foundation for the entire platform

Customer data is separated in layers: the application checks chain, location, role and relationship, and covered tables use Row Level Security. Effective isolation also depends on tenant context, database owner, grants and BYPASSRLS; cross-tenant and support paths are tested with positive and negative scenarios and are covered by the same control principle.

View GDPR and Policies
Multi-tenancy and data isolation in FlowDule (AI-genereret billede)AI-genereret indhold
Role-based access control in FlowDule (AI-genereret billede)AI-genereret indhold
Access Control

Role-based access across chain, location, and practitioner

FlowDule's role model cascades from chain to location to practitioner, with access checked on each API call. Support access to customer content may only take place for a specific, documented case, after the necessary approval, with personal identity, the shortest possible duration and relevant logging.

Read the Security description
Contact

Security enquiries

If you have found a vulnerability or have a security question about the platform, write to security@flowdule.com. We handle security enquiries as quickly as possible. General support questions should be sent to support@flowdule.com.

Write to security@flowdule.com
Next Steps

Review security and access control in practice

Create a free account and see roles, multi-tenancy, audit logs and access control in the running platform yourself. 30 days free, no credit card.