What is in place today
The public FlowHello website is served over HTTPS with TLS 1.2 or newer, HTTP Strict Transport Security, content-security controls, clickjacking protection, and browser feature restrictions. These are website protections; they are not a claim of product certification or a substitute for the CRM controls described below.
We are a studio too. Here is how we handle that.
Great Story Sound and Klangkulisse operate in the same industry as many FlowHello customers. We name that conflict rather than asking you to overlook it. FlowHello exists because we know the operational pressure studios work under, and customer data must never become an input to our studio businesses.
The FlowHello production and development Azure subscriptions are separate from Great Story Sound. Great Story Sound and Klangkulisse studio staff do not have access to the FlowHello platform. Platform administration is limited to named identities, not shared studio accounts.
Every administrative access to customer tenant data is logged in a tenant-specific record and is available to that tenant on request. Support access is handled with the customer's knowledge. Our policy is straightforward: FlowHello, Great Story Sound, Klangkulisse, and their affiliates do not access, use, or derive insight from customer tenant data for any competitive purpose. That includes using client lists, bids, rates, pipeline information, or other customer data to inform studio sales, marketing, or bidding.
How FlowHello CRM is being built
Our design goal is simple: each studio should have a clear boundary around its data. The following controls are planned architecture requirements for the CRM and will move here as deployed facts only after verification.
- Tenant isolation: per-organization databases rather than a shared customer table, with tenant-scoped private file storage and separately entitlement-gated licensed catalog data.
- Authentication and access: passwordless email one-time codes through Microsoft Entra External ID, with role-based access for owner, admin, member, and read-only users.
- Platform access: Azure managed identities and Key Vault for service access, with MFA-protected least-privilege internal administration.
- Encryption: TLS in transit and Azure platform encryption at rest for databases, storage, and backups.
The operational details we will not retrofit
Before FlowHello CRM creates a real customer invoice or serves a customer whose data requires EU residency, we are locking in the business-record conventions that are expensive and risky to change later.
- Money and currency: every monetary amount will carry an explicit ISO currency code and use precise minor units, not ambiguous floating-point values.
- Offers and invoices: once published, a document will remain a frozen record of what was issued, including the data and PDF used at that time. Customer-facing document numbers will be sequential within each tenant.
- Time that reflects your studio: the platform will store time consistently and present follow-ups, daily limits, and business dates in the tenant's configured time zone.
- Clear change history: important changes will carry a readable audit summary, so a team can see what changed without reconstructing a technical log.
People first. Agents later.
FlowHello CRM is not introducing autonomous agent identities, machine credentials, webhooks, or new external access paths in this release. Human sign-in remains passwordless email one-time codes. We are establishing an audit convention that distinguishes actions taken by people, future agents, and background systems before any agent capability is introduced.
When agent-assisted workflows are considered later, they will have separate authorization and explicit prohibitions rather than inheriting a human user's role. Customer-facing announcement waits until that capability is real, reviewable, and useful.
Data, backups, and residency
FlowHello CRM is planned to launch in the United States. EU data residency is a roadmap item, not a current promise. We will publish customer-data backup retention, restore testing, export, deletion, and backup age-out details only after those policies are configured and verified for the production CRM.
Before we describe export as available, we will verify a real tenant export in a stable format: a ZIP file with per-entity CSV files, a JSON manifest, and original customer document files. When CRM data processing begins, customer data rights will include practical access, export, correction, and deletion request paths. Licensed catalog data, where available, will remain subject to its separate license terms.
Subprocessors
For the live marketing website, FlowHello uses Microsoft Azure for hosting and form storage, and Google Analytics 4 for website analytics as described in the Privacy Policy. The CRM's final production subprocessor list, including Microsoft Entra External ID and Azure Communication Services where used, will be published and kept current before customer onboarding.
Responsible disclosure
We welcome good-faith reports of potential vulnerabilities. Please use the contact form and clearly mark your message “Security report.” We do not currently operate a bug-bounty program. We will not publish a response-time commitment until we have a monitored, role-based security contact route in place.
What we do not have yet
This is the roadmap, not a promise with artificial dates:
- Independent penetration testing before an enterprise tier.
- A SOC 2 examination as the product grows into larger facilities.
- Customer SSO with a company identity provider such as Entra ID or Okta.
- EU data residency and a public uptime and status page.
- Published CRM backup, recovery, deletion, and subprocessor details once production controls are verified.
- Dedicated customer-managed encryption keys as a future enterprise requirement, when a customer need justifies the operational cost.
- Zero-knowledge or end-to-end encryption is not planned: FlowHello must be able to search customer-authorized data, create documents, and provide the workflow features the product is built for.
We will update this page as controls become operational and their evidence is reviewed. We do not use security badges, certification marks, or blanket compliance claims that we have not earned.