Trust center
Security controls for the workflows your customers depend on.
Fluenta isolates workspaces, encrypts credentials, verifies webhooks, restricts outbound requests, and gives operators explicit access roles.
Last reviewed 2026-07-28
Security overview
Fluenta applies security controls to the workspace, credentials, integrations, and operational data used by a workflow. Technical implementation details are maintained in the security documentation for developers and security reviewers.
| Control | Current status |
|---|---|
| Encryption | HTTPS in transit and encrypted stored credentials. |
| Workspace access | Explicit owner, editor, agent, and viewer roles. |
| Integration safety | Verified inbound webhooks and guarded outbound requests. |
| Retention | Conversation data is purged after 90 days. |
Encryption
Connections to Fluenta use HTTPS in transit. Credentials used for WhatsApp and connected services are encrypted before storage and are not shown as plain text in the product interface.
Access control
Workspaces use explicit owner, editor, agent, and viewer roles. Product routes enforce the minimum role required for an action, and secret values are masked in the interface.
Tenant isolation
Workspaces are isolated so members access only the resources their workspace authorizes. Fluenta avoids revealing whether a resource exists outside a member’s workspace.
Secure integration
Fluenta verifies inbound webhooks and applies safeguards to outbound HTTP requests. Review webhook verification, request guard behavior, token scopes, redirect handling, runtime isolation, response limits, and audit events in the technical security documentation.
Data retention
Fluenta automatically purges expired conversation data after 90 days. For deletion requests and the data classes involved, read how data deletion works.
Backups and recovery
Scheduled database backups run on a timer. Restore testing and formal recovery objectives are not yet documented.
Incident response
Report a security concern through the vulnerability reporting path below. Fluenta will acknowledge receipt and use the report details to investigate the affected service.
Compliance status
Fluenta does not claim SOC 2, ISO 27001, HIPAA, PCI, or any other certification or audit.
Subprocessors
Fluenta is preparing a subprocessor list that identifies each provider by legal entity and purpose. Until that list is published, contact the team for a current review request.
Controls we are adding
The following baseline controls are not available today:
- Two-factor authentication.
- Application-level rate limiting.
- A public status page.
- Self-service data export and deletion.
- An uptime SLA.
- Tested backup restores and published RPO/RTO targets.
Vulnerability reporting
Please report a potential vulnerability to [email protected].
Include a concise description, steps to reproduce or an affected URL, the potential impact, and a safe way to contact you. We will acknowledge receipt.