Encryption · all pages

SECURITY AND YOUR DATA

Encryption

Every scope has its own key; destroying the key makes the data unreadable for good.

  • Each personal Flow and each workspace has its own data key. Content is encrypted with AES-256-GCM at rest.
  • Data keys are themselves encrypted with a master key that is never stored in the database, code or backups.
  • A stolen disk, database dump or backup yields only ciphertext.
  • Backups are encrypted with their own key and restore-tested.
  • API tokens are stored hashed; connections are rate-limited.

Encryption at rest does not protect against a compromised running server, which must read data to search it. Passphrase-locked “private” and fully offline “vault” memories are not built.

Docs version 1.1 · Something unclear or missing? Tell us.