Skip to content

SECURITY

Product security information

Flow²Test is designed with practical security-minded defaults for local API automation workflows. This page summarises principles we communicate publicly. It is not a certification claim.

Principles

How we approach product security.

  • Environment and secret handling

    Studio is designed so reusable environments, credentials and related values can be managed locally, with masking support so sensitive fields are not casually exposed in the UI.

  • Local-first workflow

    Core recording, generation and execution workflows are oriented around the desktop product running on your machine, reducing unnecessary dependency on sending project data to Flow²Test cloud services for basic automation work.

  • Secure engineering practices

    We aim to follow careful engineering practices for the website and product surfaces we operate, including keeping server-side secrets out of public client code and validating public form submissions.

  • Website enquiry handling

    Contact and Early Access forms are processed server-side. Email delivery uses dedicated infrastructure, and visitor addresses are used for Reply-To so our team can respond securely without exposing internal keys in the browser.

Security enquiries

If you believe you have discovered a security issue affecting Flow²Test, please contact support@flow2test.com with enough information for us to investigate.

Please do not publicly disclose a suspected vulnerability until we have had a reasonable opportunity to review and address it. We do not currently operate a public bug bounty programme.

Email: support@flow2test.com

This page does not claim SOC 2, ISO 27001, HIPAA, PCI, GDPR certification, penetration-test results, or specific encryption standards beyond what is described in product documentation when published.