DevFloHQ
Menu

Security overview

Practical safeguards for an invitation-only platform.

DevFloHQ is being developed carefully, with organizational isolation, limited access, and responsible data use as core requirements.

Organization isolation

Each authorized user is linked to one organization. Database row-level security restricts ordinary sessions to records belonging to that organization.

Invitation-only access

Accounts are provisioned directly. There is currently no public signup path, and access should be removed when a participant no longer needs it.

Least necessary data

Pilots should begin with limited information and avoid sensitive data. The safest useful dataset is preferred over copying an organization’s entire history.

Human review

AI-assisted outputs and automated workflows require human review. Relationship decisions, approvals, and organizational judgment remain with people.