Trust center

Security controls for the workflows your customers depend on.

Fluenta isolates workspaces, encrypts credentials, verifies webhooks, restricts outbound requests, and gives operators explicit access roles.

Last reviewed 2026-07-28

Security overview

Fluenta applies security controls to the workspace, credentials, integrations, and operational data used by a workflow. Technical implementation details are maintained in the security documentation for developers and security reviewers.

ControlCurrent status
EncryptionHTTPS in transit and encrypted stored credentials.
Workspace accessExplicit owner, editor, agent, and viewer roles.
Integration safetyVerified inbound webhooks and guarded outbound requests.
RetentionConversation data is purged after 90 days.

Encryption

Connections to Fluenta use HTTPS in transit. Credentials used for WhatsApp and connected services are encrypted before storage and are not shown as plain text in the product interface.

Access control

Workspaces use explicit owner, editor, agent, and viewer roles. Product routes enforce the minimum role required for an action, and secret values are masked in the interface.

Tenant isolation

Workspaces are isolated so members access only the resources their workspace authorizes. Fluenta avoids revealing whether a resource exists outside a member’s workspace.

Secure integration

Fluenta verifies inbound webhooks and applies safeguards to outbound HTTP requests. Review webhook verification, request guard behavior, token scopes, redirect handling, runtime isolation, response limits, and audit events in the technical security documentation.

Data retention

Fluenta automatically purges expired conversation data after 90 days. For deletion requests and the data classes involved, read how data deletion works.

Backups and recovery

Scheduled database backups run on a timer. Restore testing and formal recovery objectives are not yet documented.

Incident response

Report a security concern through the vulnerability reporting path below. Fluenta will acknowledge receipt and use the report details to investigate the affected service.

Compliance status

Fluenta does not claim SOC 2, ISO 27001, HIPAA, PCI, or any other certification or audit.

Subprocessors

Fluenta is preparing a subprocessor list that identifies each provider by legal entity and purpose. Until that list is published, contact the team for a current review request.

Controls we are adding

The following baseline controls are not available today:

  • Two-factor authentication.
  • Application-level rate limiting.
  • A public status page.
  • Self-service data export and deletion.
  • An uptime SLA.
  • Tested backup restores and published RPO/RTO targets.

Vulnerability reporting

Please report a potential vulnerability to [email protected].

Include a concise description, steps to reproduce or an affected URL, the potential impact, and a safe way to contact you. We will acknowledge receipt.