SECURITY
Product security information
Flow²Test is designed with practical security-minded defaults for local API automation workflows. This page summarises principles we communicate publicly. It is not a certification claim.
Principles
How we approach product security.
Environment and secret handling
Studio is designed so reusable environments, credentials and related values can be managed locally, with masking support so sensitive fields are not casually exposed in the UI.
Local-first workflow
Core recording, generation and execution workflows are oriented around the desktop product running on your machine, reducing unnecessary dependency on sending project data to Flow²Test cloud services for basic automation work.
Secure engineering practices
We aim to follow careful engineering practices for the website and product surfaces we operate, including keeping server-side secrets out of public client code and validating public form submissions.
Website enquiry handling
Contact and Early Access forms are processed server-side. Email delivery uses dedicated infrastructure, and visitor addresses are used for Reply-To so our team can respond securely without exposing internal keys in the browser.
Security enquiries
If you believe you have discovered a security issue affecting Flow²Test, please contact support@flow2test.com with enough information for us to investigate.
Please do not publicly disclose a suspected vulnerability until we have had a reasonable opportunity to review and address it. We do not currently operate a public bug bounty programme.
Email: support@flow2test.com
This page does not claim SOC 2, ISO 27001, HIPAA, PCI, GDPR certification, penetration-test results, or specific encryption standards beyond what is described in product documentation when published.