Trust
Security at FlowSuite
Our approach to protecting accounts, approval data, and connections to your Snipe-IT environment.
Security is a shared responsibility. This page describes FlowSuite's current security approach and the steps customers should take when connecting their systems. It is not a certification or a guarantee that security incidents can never occur.
1. Data in Transit
FlowSuite's public website and application use HTTPS to protect information while it travels between supported browsers, FlowSuite, and connected services. Customers should connect only to Snipe-IT endpoints that use valid HTTPS certificates.
2. Account and Tenant Access
Application access is authenticated and scoped to the customer's tenant. Role-based permissions are used to limit administrative and workflow actions. Sensitive state-changing requests include server-side authorization and request-forgery protections.
3. Snipe-IT Credentials
Connection credentials are treated as sensitive configuration. Customers should create a dedicated Snipe-IT API token with only the permissions needed for FlowSuite, avoid sharing it, and rotate or revoke it promptly if compromise is suspected.
4. Application Protections
FlowSuite applies input validation, tenant-isolation checks, signed webhook verification where integrations support it, rate limiting on sensitive flows, and audit-oriented logging. We review and improve these safeguards as the product changes.
5. Operational Security
Access to production systems is restricted to authorized personnel with a business need. Secrets are not intended to be stored in public source code. Backups, monitoring, software updates, and incident handling are managed according to operational risk and service requirements.
6. Customer Responsibilities
- Use unique, strong passwords and protect access to account email addresses;
- Invite only authorized team members and remove access when it is no longer required;
- Use least-privilege Snipe-IT API tokens and keep Snipe-IT updated;
- Review workflow permissions and approval rules before production use; and
- Report suspicious activity or suspected credential exposure promptly.
7. Security Incidents
If we confirm an incident affecting customer information, we will investigate, contain the issue, take reasonable corrective action, and provide notifications when required by applicable law or a customer agreement.
8. Report a Vulnerability
Send security concerns to support@flowsuite.solutions with the subject “FlowSuite security report.” Include a clear description, affected URL or feature, reproduction steps, and potential impact. Do not access another customer's data, disrupt the service, or publish sensitive details before we have had a reasonable opportunity to investigate. FlowSuite does not currently operate a paid bug-bounty program.
9. Privacy
For information about the personal data we collect and how it is used, see our Privacy Policy.
← Back to homepage