Security

Last updated August 2026

A quick overview of how we protect your account and workspace data.

Authentication

Passwords are hashed with a salted, industry-standard algorithm — we never store or have access to your plaintext password.

Sessions are secured with signed, HTTP-only cookies so they can't be read or tampered with by client-side scripts.

Data isolation

Every request is authenticated and scoped to your account server-side — task and team data is never returned for a user who isn't a verified member.

Team workspaces enforce role-based access on every read and write, not just in the interface: a team member can only ever see tasks assigned to them, checked again on the server for every request.

Infrastructure

Data is stored in a managed Postgres database with encryption at rest and in transit (TLS).

Billing is handled entirely by Polar — we never see or store your card details.

Reporting an issue

If you believe you've found a security issue, please email us directly rather than filing a public report — we take these seriously and respond quickly.

info@flowshot.app