Trust & security

How we protect what you sign

FlowSign is designed so that the important documents you send and sign are secure in transit, secure at rest, and defensible under New Zealand privacy law. This page is the one-stop for procurement, IT and compliance reviews.

Legal documents last updated: September 2026 · Version v2026-09-09

Security posture

Encryption everywhere

TLS in transit and AES-256 encryption at rest through our infrastructure providers for stored documents and databases. Signed PDFs live in access-controlled object storage.

Staff access with 2FA

Principle of least privilege for staff. Administrative access is via Google Workspace single sign-on with mandatory two-factor authentication.

Tenant isolation

Every customer-scoped database query is filtered by organisation identifier so one customer's documents and audit trail cannot be returned to another. Object storage is protected by scoped, short-lived signed URLs.

Audit log of security events

Every security-relevant action is recorded and retained for the life of the associated document. Purge redacts identifiers but keeps the event.

Legal commitments

Our contractual and privacy commitments are published and versioned. Read them in full:

Our Privacy Officer is Anna Woodward - reach her at privacy@flowsign.app. Business customers can request a signed Data Processing Addendum by emailing legal@flowsign.app.

Security roadmap

We take security posture seriously and are open about where we're headed. Items we are actively working towards:

  • ISO 27001 information-security alignment as the business scales.
  • Published uptime and status page once we have meaningful production data.
  • A public bug-bounty programme once the disclosure process is battle-tested.

If a certification or specific control is important to your procurement process, we are happy to walk you through where we stand. Email legal@flowsign.app.

Report a security issue

Found something? Please tell us.

Email security@flowsign.app with a description of the issue and steps to reproduce. We aim to acknowledge reports within one business day, keep you updated as we investigate, and credit you (if you would like credit) once the issue is resolved. Please give us a reasonable time to fix an issue before publishing it.