Back to Legal
Security

Security at SmartFlow.

SmartFlow AI Technology Limited operates Ghost Protocol on behalf of teams that handle sensitive operational data every day. Security is a first-class product requirement — designed into the platform, embedded in our engineering practice, and audited continuously.

Product security

  • Single sign-on with SAML 2.0 and OIDC for enterprise plans
  • Role-based access control with granular workspace permissions
  • Detailed audit logs for authentication and configuration changes
  • Scoped API keys with rotation and revocation
  • Secrets vault with envelope encryption for connected-source credentials

Infrastructure security

  • Hosted on tier-1 cloud providers with hardened, isolated tenancy
  • Network segmentation, private subnets, and least-privilege IAM
  • Encrypted backups with periodic restore tests
  • Multi-region disaster recovery posture for production workloads
  • Continuous infrastructure monitoring and anomaly alerting

Data protection

  • TLS 1.2+ for data in transit across all public endpoints
  • AES-256 encryption for data at rest, including managed databases and object storage
  • Customer-data isolation enforced at the application and database layer
  • Regional data-residency options for enterprise customers
  • Data Processing Addendum available for customers subject to GDPR or UK GDPR

Application security

  • Secure SDLC with mandatory peer code review
  • Static analysis and dependency scanning on every change
  • Automated container and image scanning in CI
  • Annual third-party penetration testing of Ghost Protocol
  • Internal red-team exercises focused on AI-specific risks

People & operations

  • Background checks for employees with production access
  • Least-privilege production access gated by MFA
  • Mandatory annual security and privacy training
  • Documented incident-response runbooks and on-call rotation
  • Vendor risk reviews for all subprocessors

Privacy & compliance

  • GDPR and UK GDPR aligned data-protection program
  • Subprocessor list available on request
  • Standard Contractual Clauses for international transfers
  • Compliance roadmap aligned to SOC 2 and ISO/IEC 27001 — contact us for the current attestation status

Authentication & access

Enterprise workspaces support SSO via SAML 2.0 and OIDC, SCIM provisioning, enforced MFA, IP allow-listing, and session-lifetime policies. Workspace admins can manage roles, scoped API keys, and audit logs from a single console.

AI model handling

Ghost Protocol routes requests to vetted model providers under data-protection terms that prohibit training on customer content. Enterprise plans support bring-your-own-key and private model endpoints for sensitive workloads.

Logging & monitoring

Production systems emit structured audit and security logs to a centralized SIEM with retention, alerting, and tamper-evident storage. Customer-facing audit logs are exportable from the workspace console.

Incident response

SmartFlow maintains a documented incident-response process with a 24/7 on-call rotation. Confirmed incidents that affect customer data are communicated to impacted customers within the timeframe required by applicable law and the Master Enterprise Terms.

Responsible disclosure

If you believe you have discovered a security vulnerability in Ghost Protocol or any SmartFlow service, please report it to security@smart-flowai.com. We commit to acknowledging reports promptly, investigating in good faith, and not pursuing legal action against researchers who follow this policy.

Please avoid privacy violations, service disruption, and access to data that is not your own while testing. Provide enough information for our team to reproduce and validate the issue.

© 2026 SmartFlow AI Technology Limited.