Authentication & SSO
OpenID Connect / OAuth2 via Keycloak, Red Hat SSO or EntraID, with short-lived signed tokens, refresh/revocation, session timeouts and step-up MFA. One identity model across every microservice.
Platform · Security & Compliance
An AI system in banking, insurance or healthcare has to prove it behaves. FlowX.AI wires governance into live AI data — so you walk into an audit with the record already built.
iso 27001 certified · soc 2 type i · zero-trust by default
Most vendors treat compliance as a spreadsheet you fill in after the fact. FlowX makes it built in: the same platform that runs your agents proves they were safe.
Every decision is traced, every policy is checked against what actually happened, and every artifact an auditor asks for is collected as the system runs — the difference between a compliance posture on paper and evidence you can hand over on the day.
Observatory 2.0 · governance over live AI dataEnterprise-grade access, privacy and governance — applied uniformly across every agent, workspace and journey.
OpenID Connect / OAuth2 via Keycloak, Red Hat SSO or EntraID, with short-lived signed tokens, refresh/revocation, session timeouts and step-up MFA. One identity model across every microservice.
Fine-grained roles scoped per component, enforced across control plane and data planes. Realm scoping, tenant-aware authorization and per-tenant storage keep workspaces fully isolated.
TLS 1.2+ in transit (1.3 preferred) and mTLS between services; AES-256 at rest. Customer-managed keys via AWS KMS, Azure Key Vault or HashiCorp Vault — no plaintext key material exposed.
Every action logged with actor, resource, outcome and timestamp; BPMN node-level execution traces via OpenTelemetry, exportable to your SIEM. Retention and verbosity are configurable.
No implicit trust — every component continuously authenticates. Rate limits, scoped permissions, mutual TLS and isolated agent runtimes minimize lateral movement and blast radius.
Design-time PII tagging masks sensitive fields in views, logs and monitoring; stateless LLM calls, configurable retention, GDPR erasure/DSR workflows, and no training on your data by default.
Each ships as a policy pack broken into requirements, with the evidence and assessments pre-mapped, and you can add your own frameworks. These are what the platform maps for your workloads; FlowX.AI’s own attestations are below.
Risk-based regulation for AI systems
Data privacy & protection
Healthcare data protection
Security, availability, confidentiality
Payment card data security
Information security management
Separate from what the platform maps for you: the attestations FlowX.AI itself has obtained. The full statement, and how to request the documents, is on the Trust & Compliance page.
An information security management system certified against ISO/IEC 27001, covering how FlowX.AI governs and runs security across the company.
Independent examination against the AICPA Trust Services Criteria; controls suitably designed as of June 17, 2026. SOC 2 Type II, which tests the controls over an operating period, is in progress.
Personal data processed under the GDPR: processing terms with customers, defined retention, subject-rights handling, privacy by design.
SOC 2 Type I report available under NDA: request it →
The high-risk provisions apply from 2 August 2026, with penalties up to €15M or 3% of worldwide turnover. Here is where each core requirement lands in the platform.
| Article | Requirement | How FlowX meets it |
|---|---|---|
| Art. 9 | Risk management system across the lifecycle | Online monitoring, custom evaluators, alert thresholds |
| Art. 10 | Data governance & bias prevention | PII detection + redaction, bias evaluators, policy engine |
| Art. 12 | Automatic event logging over the system’s lifetime | End-to-end tracing with configurable retention |
| Art. 13 | Transparency & interpretable outputs | Full execution traces and visual workflow graphs |
| Art. 14 | Human oversight & intervention | Pause nodes, annotation queues, decision routing |
| Art. 15 | Accuracy metrics & adversarial resilience | 13-metric LLM-as-Judge + adversarial evaluators |
| Art. 72 | Post-market monitoring | Statistical drift detection with real-time alerting |
| GDPR Art. 32 | Technical measures for data protection | PII redaction, encryption, RBAC, audit logging |
Read more: Safety & governance — the AI-native controls → · Observatory →
Security is built into how the platform is developed and shipped — not inspected in at the end.
Threat modelling, OWASP secure-coding standards, and independent penetration testing as part of every assurance cycle.
Container images scanned and pinned by digest; signed release artifacts with an SBOM per release and a formal patch-management process.
Reproducible, repeatable deployments and rollbacks via GitOps, with automated DB migrations and environment promotion Dev → UAT → Prod.
Bring one regulated journey and your compliance checklist. We'll show the platform running it — with the traces, policies and evidence an audit actually asks for.