
Encryption at rest and in transit
Communication with FlowDule is protected by modern transport encryption, and the approved production baseline uses encryption at rest for relevant databases, files and sensitive fields.
This section describes the security mechanisms that protect data across chains, locations, and roles - from encryption and multi-tenancy to logging and multi-factor authentication for privileged access.

FlowDule is built with multi-tenancy from day one, where chains, locations, and users are separated. Security is not an extra layer - it's integral to how data is stored, accessed, and logged.
This page describes the key mechanisms in outline. The binding security level follows from the accepted Data Processing Agreement, the customer annex and the version-bound TOMs annex, and the Security description gives the overall picture.
Encryption, isolation, access, and traceability
Customer data is separated in layers: the application checks chain, location, role and relationship, and covered tables use Row Level Security. Effective isolation also depends on tenant context, database owner, grants and BYPASSRLS; cross-tenant and support paths are tested with positive and negative scenarios and are covered by the same control principle.
View GDPR and Policies

FlowDule's role model cascades from chain to location to practitioner, with access checked on each API call. Support access to customer content may only take place for a specific, documented case, after the necessary approval, with personal identity, the shortest possible duration and relevant logging.
Read the Security descriptionIf you have found a vulnerability or have a security question about the platform, write to security@flowdule.com. We handle security enquiries as quickly as possible. General support questions should be sent to support@flowdule.com.
Write to security@flowdule.comCreate a free account and see roles, multi-tenancy, audit logs and access control in the running platform yourself. 30 days free, no credit card.