Draft, then approve
People review outputs before client-facing or business-critical action.
Human approval and security
AI output is treated as a draft. Client-facing and business-critical actions remain controlled, while provider integrations stay server-side and each workflow is configured for the agreed client scope.
People review outputs before client-facing or business-critical action.
Provider integrations and secret credentials remain outside browser code.
Data and notifications are separated through client-specific configuration.
Security overview
FlowOps AI applies risk-based safeguards including separated client configuration, restricted secrets, access controls, request protection and human review for AI-assisted outputs. Security is shared between FlowOps, the client and approved providers; no system is guaranteed to resist every threat.
HTTPS and security headers. Vercel Firewall rules and API rate limits. Dashboard bearer-token access. Client source tokens for live lead intake. Audit logging for key actions. Google Sheets formula injection protection.
AI outputs are drafts, summaries and suggestions. A human should approve important customer, legal, financial or operational decisions.
Clients remain responsible for authorised users, lawful source access, credential protection and prompt reporting of suspected misuse. FlowOps investigates relevant incidents and communicates material information without undue delay according to the facts, contractual roles and applicable obligations.
Approved workflows may rely on hosting, email, storage or AI providers. Their availability and security posture are reviewed as part of the relevant scope, but FlowOps does not control every provider outage or policy change. Client-specific controls belong in the Order Form and, where required, the DPA.