Organization isolation
Each authorized user is linked to one organization. Database row-level security restricts ordinary sessions to records belonging to that organization.
Security overview
DevFloHQ is being developed carefully, with organizational isolation, limited access, and responsible data use as core requirements.
Each authorized user is linked to one organization. Database row-level security restricts ordinary sessions to records belonging to that organization.
Accounts are provisioned directly. There is currently no public signup path, and access should be removed when a participant no longer needs it.
Pilots should begin with limited information and avoid sensitive data. The safest useful dataset is preferred over copying an organization’s entire history.
AI-assisted outputs and automated workflows require human review. Relationship decisions, approvals, and organizational judgment remain with people.
DevFloHQ is an early-stage product and has not been represented as independently security audited, SOC 2 certified, HIPAA compliant, or suitable for regulated sensitive data. Security needs should be discussed before onboarding, especially when a proposed workflow involves confidential or legally protected information.
Send security concerns directly to nick.rossi410@gmail.com. Do not include passwords, access tokens, or confidential records in the initial message.