Trust & Security
This pack contains 18 working-draft legal documents. None of them have been reviewed by Texas counsel or counsel licensed in any other jurisdiction. They are a starting point for a real attorney engagement, not a finished publication. Brackets [highlight] indicate custom options to finalize.
SiteFlows is built on the premise that trust is the product. This page describes the technical, organizational, and operational controls we use to keep your data safe.
1. Data Security
- Encryption in transit: TLS 1.3 enforced across all public endpoints.
- Encryption at rest: AES-256 across all production databases and object storage.
- Field-level encryption for tax IDs, bank account numbers, and other secrets, in addition to volume-level encryption.
- Key management: AWS KMS with separation of duties; production keys are not accessible to engineering.
2. Access Controls
- Role-based access control with least-privilege principles.
- All production access logged and reviewed monthly.
- Tenant isolation enforced at the application and database layers; cross-tenant probe tests run on every CI build.
3. Application Security
- Static code analysis on every pull request.
- Dependency vulnerability scanning, with SLA for remediation by severity.
- Secret scanning to prevent credential commits.
- Content Security Policy and modern security headers on all web surfaces.
4. Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities. Email security@siteflows.ai with your contact information. We commit to: security@siteflows.ai
- acknowledge receipt within 24 hours;
- provide a triage update within 5 business days;
- not pursue legal action against good-faith researchers who follow responsible disclosure;
- credit researchers (with permission) once the issue is fixed.
A formal bug bounty is on the roadmap (target: Q3 2026). Q3 2026).
5. Incident Response
- Documented incident response plan with 24×7 on-call rotation.
- Internal escalation within 1 hour of confirmed incident.
- Customer notification within 72 hours for any Personal Data Breach affecting their data, in accordance with the DPA.
- Post-incident report shared with affected Operators within 30 days.
6. Backup & Disaster Recovery
- Daily encrypted backups of all customer data.
- 35-day backup retention with point-in-time recovery for the previous 7 days.
- Quarterly disaster recovery exercises.
- Recovery Time Objective (RTO): 4 hours. Recovery Point Objective (RPO): 1 hour.
7. Personnel Security
- Background checks for personnel with production access.
- Confidentiality and IP-assignment agreements for all employees and contractors.
- Annual security training, including phishing simulations.
- Off-boarding includes immediate revocation of all access on the same business day.
8. Compliance Roadmap
9. Sub-processors
See Sub-processor List for the current set.
10. Contact
For security questions and security questionnaires, allow 5 business days for response; SOC 2 reports (when issued) are available under NDA.