Authentication & SSO
OpenID Connect / OAuth2 via Keycloak, Red Hat SSO or EntraID, with short-lived signed tokens, refresh/revocation, session timeouts and step-up MFA. One identity model across every microservice.
Platform · Security & Compliance
An AI system in banking, insurance or healthcare has to prove it behaves. FlowX.AI wires governance into live AI data — so you walk into an audit with the record already built.
iso 27001 certified · zero-trust by default
Most vendors treat compliance as a spreadsheet you fill in after the fact. FlowX makes it built in: the same platform that runs your agents proves they were safe.
Every decision is traced, every policy is checked against what actually happened, and every artifact an auditor asks for is collected as the system runs — the difference between a compliance posture on paper and evidence you can hand over on the day.
Observatory 2.0 · governance over live AI dataEnterprise-grade access, privacy and governance — applied uniformly across every agent, workspace and journey.
OpenID Connect / OAuth2 via Keycloak, Red Hat SSO or EntraID, with short-lived signed tokens, refresh/revocation, session timeouts and step-up MFA. One identity model across every microservice.
Fine-grained roles scoped per component, enforced across control plane and data planes. Realm scoping, tenant-aware authorization and per-tenant storage keep workspaces fully isolated.
TLS 1.2+ in transit (1.3 preferred) and mTLS between services; AES-256 at rest. Customer-managed keys via AWS KMS, Azure Key Vault or HashiCorp Vault — no plaintext key material exposed.
Every action logged with actor, resource, outcome and timestamp; BPMN node-level execution traces via OpenTelemetry, exportable to your SIEM. Retention and verbosity are configurable.
No implicit trust — every component continuously authenticates. Rate limits, scoped permissions, mutual TLS and isolated agent runtimes minimize lateral movement and blast radius.
Design-time PII tagging masks sensitive fields in views, logs and monitoring; stateless LLM calls, configurable retention, GDPR erasure/DSR workflows, and no training on your data by default.
Each ships as a policy pack broken into requirements, with the evidence and assessments pre-mapped. FlowX.AI is ISO 27001 certified, with SOC 2 attestation in progress — and you can add your own frameworks.
Risk-based regulation for AI systems
Data privacy & protection
Healthcare data protection
Security, availability, confidentiality
Payment card data security
Information security management
The high-risk provisions apply from 2 August 2026, with penalties up to €15M or 3% of worldwide turnover. Here is where each core requirement lands in the platform.
| Article | Requirement | How FlowX meets it |
|---|---|---|
| Art. 9 | Risk management system across the lifecycle | Online monitoring, custom evaluators, alert thresholds |
| Art. 10 | Data governance & bias prevention | PII detection + redaction, bias evaluators, policy engine |
| Art. 12 | Automatic event logging over the system’s lifetime | End-to-end tracing with configurable retention |
| Art. 13 | Transparency & interpretable outputs | Full execution traces and visual workflow graphs |
| Art. 14 | Human oversight & intervention | Pause nodes, annotation queues, decision routing |
| Art. 15 | Accuracy metrics & adversarial resilience | 13-metric LLM-as-Judge + adversarial evaluators |
| Art. 72 | Post-market monitoring | Statistical drift detection with real-time alerting |
| GDPR Art. 32 | Technical measures for data protection | PII redaction, encryption, RBAC, audit logging |
Read more: Safety & governance — the AI-native controls → · Observatory →
Security is built into how the platform is developed and shipped — not inspected in at the end.
Threat modelling, OWASP secure-coding standards, and independent penetration testing as part of every assurance cycle.
Container images scanned and pinned by digest; signed release artifacts with an SBOM per release and a formal patch-management process.
Reproducible, repeatable deployments and rollbacks via GitOps, with automated DB migrations and environment promotion Dev → UAT → Prod.
Bring one regulated journey and your compliance checklist. We'll show the platform running it — with the traces, policies and evidence an audit actually asks for.