Skip to content

Start with what we do not have.

The refusals come first. A security page that opens with its strengths is the one you have to read twice.

What Flowboard does not have

No SSO and no SAML
Sign-in is email and password, or a Google account. There is no SAML path, so a client IT review that mandates one will not approve Flowboard.
No certifications
We hold no SOC 2, no ISO 27001 and no HIPAA attestation. We will not imply otherwise, and there is no trust-badge row on this page for that reason.
No public API
API key management ships inside the app, but there is no verified request-authenticated consumer behind it. Until there is, treat the API as unavailable rather than undocumented.
No MCP or agent access
Nothing in Flowboard is reachable by an external agent today.

What is here, named exactly as it is scoped

Workspace audit log
Owner and Admin only, paginated and filterable. It records created, updated, deleted, status-changed and visibility-changed across eight entity types: tasks, projects, members, invoices, sections, comments, time entries and clients.
When someone asks who moved a task out of client view, the answer is a filter, not a memory.
Cost rates are stripped by role
What a team member costs is returned only to Owner and Admin. Everyone else, clients included, sees billable rates.
You can put a project in front of a client without a rate card leaking with it.
Client logins are a separate identity
Portal users live in their own table, keyed by client, not in the members table. A client login is not a member record that happens to be restricted.
That separation is also why client seats stay free: only members count against the plan.
Visibility scoping on tasks, comments and files
The portal shows only tasks marked client-visible or client-editable, and only comments marked client-visible. “Preview as Client” applies that same rule rather than a separate mock.
What you preview is what they get, so the check takes one click instead of a second login.
Calendar tokens are encrypted at rest
Google Calendar OAuth tokens are stored with Fernet symmetric encryption, not in plaintext.
Connecting a calendar does not leave a reusable credential sitting in the database.
GDPR export
An async export job that produces a download link with a 24-hour time to live.
A data request is a job you run, not a ticket you file with us.

If a refusal above is the dealbreaker

Then this is the wrong tool for that account, and that is a straight answer. It costs both of us less than finding out in week three of an onboarding. If your client's review will not approve a tool without SAML, buy something that has it.

So what: when a client's procurement form asks, the answer is on this page either way.

Read the list of what we do not have before you read the rest.