Security
Last updated August 2026
A quick overview of how we protect your account and workspace data.
Authentication
Passwords are hashed with a salted, industry-standard algorithm — we never store or have access to your plaintext password.
Sessions are secured with signed, HTTP-only cookies so they can't be read or tampered with by client-side scripts.
Data isolation
Every request is authenticated and scoped to your account server-side — task and team data is never returned for a user who isn't a verified member.
Team workspaces enforce role-based access on every read and write, not just in the interface: a team member can only ever see tasks assigned to them, checked again on the server for every request.
Infrastructure
Data is stored in a managed Postgres database with encryption at rest and in transit (TLS).
Billing is handled entirely by Polar — we never see or store your card details.
Reporting an issue
If you believe you've found a security issue, please email us directly rather than filing a public report — we take these seriously and respond quickly.
info@flowshot.app