Platform · Security & Compliance

Built forregulated work.

An AI system in banking, insurance or healthcare has to prove it behaves. FlowX.AI wires governance into live AI data — so you walk into an audit with the record already built.

iso 27001 certified · zero-trust by default

Most vendors treat compliance as a spreadsheet you fill in after the fact. FlowX makes it built in: the same platform that runs your agents proves they were safe.

Every decision is traced, every policy is checked against what actually happened, and every artifact an auditor asks for is collected as the system runs — the difference between a compliance posture on paper and evidence you can hand over on the day.

Observatory 2.0 · governance over live AI data
Controls

The controls underneath.

Enterprise-grade access, privacy and governance — applied uniformly across every agent, workspace and journey.

Access

Authentication & SSO

OpenID Connect / OAuth2 via Keycloak, Red Hat SSO or EntraID, with short-lived signed tokens, refresh/revocation, session timeouts and step-up MFA. One identity model across every microservice.

Roles

RBAC & tenant isolation

Fine-grained roles scoped per component, enforced across control plane and data planes. Realm scoping, tenant-aware authorization and per-tenant storage keep workspaces fully isolated.

Crypto

Encryption & keys

TLS 1.2+ in transit (1.3 preferred) and mTLS between services; AES-256 at rest. Customer-managed keys via AWS KMS, Azure Key Vault or HashiCorp Vault — no plaintext key material exposed.

Trace

Audit & traceability

Every action logged with actor, resource, outcome and timestamp; BPMN node-level execution traces via OpenTelemetry, exportable to your SIEM. Retention and verbosity are configurable.

Runtime

Zero-trust runtime

No implicit trust — every component continuously authenticates. Rate limits, scoped permissions, mutual TLS and isolated agent runtimes minimize lateral movement and blast radius.

Data

Data protection

Design-time PII tagging masks sensitive fields in views, logs and monitoring; stateless LLM calls, configurable retention, GDPR erasure/DSR workflows, and no training on your data by default.

Regulatory frameworks

Six frameworks, out of the box.

Each ships as a policy pack broken into requirements, with the evidence and assessments pre-mapped. FlowX.AI is ISO 27001 certified, with SOC 2 attestation in progress — and you can add your own frameworks.

EU AI Act

Risk-based regulation for AI systems

GDPR

Data privacy & protection

HIPAA

Healthcare data protection

SOC 2

Security, availability, confidentiality

PCI-DSS

Payment card data security

ISO 27001

Information security management

EU AI Act

Mapped to the Act, article by article.

The high-risk provisions apply from 2 August 2026, with penalties up to €15M or 3% of worldwide turnover. Here is where each core requirement lands in the platform.

ArticleRequirementHow FlowX meets it
Art. 9Risk management system across the lifecycleOnline monitoring, custom evaluators, alert thresholds
Art. 10Data governance & bias preventionPII detection + redaction, bias evaluators, policy engine
Art. 12Automatic event logging over the system’s lifetimeEnd-to-end tracing with configurable retention
Art. 13Transparency & interpretable outputsFull execution traces and visual workflow graphs
Art. 14Human oversight & interventionPause nodes, annotation queues, decision routing
Art. 15Accuracy metrics & adversarial resilience13-metric LLM-as-Judge + adversarial evaluators
Art. 72Post-market monitoringStatistical drift detection with real-time alerting
GDPR Art. 32Technical measures for data protectionPII redaction, encryption, RBAC, audit logging

Read more: Safety & governance — the AI-native controls → · Observatory →

Secure delivery

Secure from commit to cluster.

Security is built into how the platform is developed and shipped — not inspected in at the end.

Build

Secure SDLC

Threat modelling, OWASP secure-coding standards, and independent penetration testing as part of every assurance cycle.

  • Threat modelling
  • SAST
  • DAST
  • Pen testing
Supply

Supply-chain assurance

Container images scanned and pinned by digest; signed release artifacts with an SBOM per release and a formal patch-management process.

  • SBOM per release
  • Grype
  • Trivy
  • Signed images
Deliver

GitOps delivery

Reproducible, repeatable deployments and rollbacks via GitOps, with automated DB migrations and environment promotion Dev → UAT → Prod.

  • ArgoCD
  • Helm
  • Digest pinning
  • Runbooks
Next

Bring yourauditors.

Bring one regulated journey and your compliance checklist. We'll show the platform running it — with the traces, policies and evidence an audit actually asks for.