myflow Trust Contact security
Security

How myflow protects customer data.

The day-to-day technical and organisational measures we use to keep your data safe — described in plain language, without exaggeration.

Hosting region
EU
Encryption in transit
TLS 1.2+
Encryption at rest
AES-256
MFA on admin access
Required

Hosting and network

myflow production workloads run in data centres located inside the European Union. We use Tier-3+ providers with redundant power, cooling and network paths, ISO 27001 certified at the facility level.

Access control

Production access is limited to a small number of named engineers on a least-privilege basis. Every administrative account is protected with multi-factor authentication; shared accounts are not used.

Application security

Security is part of how myflow is built, not a layer bolted on afterwards.

Vulnerability management

We welcome reports from security researchers. If you believe you've found a vulnerability in myflow, please email oliver@myflow.se. We'll acknowledge within two business days and keep you updated.

Endpoint and people security

Incident response

We maintain a documented incident response process covering detection, triage, containment, eradication, recovery and post-incident review. Customers affected by a security incident involving their data will be notified without undue delay and given the information needed to meet their own regulatory obligations.

Logging and monitoring