Security
A governance tool has to hold itself to the higher standard
FlowSentinel holds credentials for your most sensitive systems. Here is how they are protected and how access is enforced.
Controls
How your data is protected
Encrypted credentials
Portal tokens are encrypted before storage. Decryption happens only inside a server-side scan and never in the browser.
No credential reads from the client
The stored secret columns are unreadable to signed-in application users. Only privileged backend processes can access them.
Row-level isolation
Every table enforces row-level security. Records are scoped to the portals a person is a member of.
Invite-only accounts
There is no public sign-up. Accounts are provisioned from an approved allow-list and deactivation locks a user out immediately.
Server-side authorisation
Role and portal checks run on the server for every action, not just when a page loads.
Least-privilege HubSpot access
Scanning only reads. The few write permissions FlowSentinel holds are used solely when an administrator approves a specific remediation or provisioning action, and every one is recorded in the audit trail.
Two-factor sign-in
SMS verification through Twilio Verify and single-use recovery codes protect FlowSentinel accounts on every plan. Owners can require it for privileged roles.
SOC 2 and ISO 27001 support
Quarterly access recertification with named reviewer sign-off, a complete audit trail and anomaly alerts make your access controls easier to audit, track and evidence for both frameworks.
FlowSentinel is not itself SOC 2 or ISO 27001 certified. It supports your own programme by producing the access-review evidence your auditors ask for.
Compliance
ISO 27001 and SOC 2 evidence
Access reviews are where most ISO 27001 and SOC 2 audits stall. FlowSentinel runs quarterly access recertification with named reviewer sign-off, records every keep, change and revoke decision, and exports a complete evidence CSV, alongside a continuous audit trail, anomaly alerts and automated penetration testing. FlowSentinel is not itself certified or attested; it makes your own programme easier to audit, track and evidence.
Operations
How scans are run
- Scheduled scans are triggered by the database scheduler against authenticated internal endpoints, protected by a shared secret held in a vault.
- Each job takes a single-flight lock, so a manual re-run can never overlap a scheduled run. Expired locks are surfaced to administrators.
- Long passes over large contact sets resume from a stored cursor rather than starting again, so no records are silently skipped.
- Scan failures are recorded with the portal, the error and a timestamp, and shown in the administrator scan status panel.