SECURITY AND YOUR DATA
Encryption
Every scope has its own key; destroying the key makes the data unreadable for good.
- Each personal Flow and each workspace has its own data key. Content is encrypted with AES-256-GCM at rest.
- Data keys are themselves encrypted with a master key that is never stored in the database, code or backups.
- A stolen disk, database dump or backup yields only ciphertext.
- Backups are encrypted with their own key and restore-tested.
- API tokens are stored hashed; connections are rate-limited.
Encryption at rest does not protect against a compromised running server, which must read data to search it. Passphrase-locked “private” and fully offline “vault” memories are not built.