Security
Security controls and GDPR-aligned data handling by design
Flotr supports GDPR-aligned operations through authenticated, workspace-scoped access, role controls, and traceable operational changes. We apply data-protection principles throughout the product and review customer-specific requirements directly.
Workspace-scoped data access
Business data is accessed through repositories that apply the active workspace boundary. API requests require an authenticated user and active organization.
Roles and permissions
Workspace roles control sensitive actions such as inviting members, managing integrations and automations, viewing audit history, and managing billing.
Modern authentication
Flotr supports Google sign-in, email magic links, and passkeys. Sessions and organization membership are managed with Better Auth.
Operational audit history
Meaningful changes emit domain events that feed operation activity and workspace audit records. This supports traceability but is not a certification.
Before using regulated or sensitive data
Ask us about your hosting, retention, access, data-processing, and contractual requirements. Product features do not replace your own security review, legal advice, or compliance program.
Contact Flotr about security