Start with what we do not have.
The refusals come first. A security page that opens with its strengths is the one you have to read twice.
What Flowboard does not have
- No SSO and no SAML
- Sign-in is email and password, or a Google account. There is no SAML path, so a client IT review that mandates one will not approve Flowboard.
- No certifications
- We hold no SOC 2, no ISO 27001 and no HIPAA attestation. We will not imply otherwise, and there is no trust-badge row on this page for that reason.
- No public API
- API key management ships inside the app, but there is no verified request-authenticated consumer behind it. Until there is, treat the API as unavailable rather than undocumented.
- No MCP or agent access
- Nothing in Flowboard is reachable by an external agent today.
What is here, named exactly as it is scoped
- Workspace audit log
- Owner and Admin only, paginated and filterable. It records created, updated, deleted, status-changed and visibility-changed across eight entity types: tasks, projects, members, invoices, sections, comments, time entries and clients.
- When someone asks who moved a task out of client view, the answer is a filter, not a memory.
- Cost rates are stripped by role
- What a team member costs is returned only to Owner and Admin. Everyone else, clients included, sees billable rates.
- You can put a project in front of a client without a rate card leaking with it.
- Client logins are a separate identity
- Portal users live in their own table, keyed by client, not in the members table. A client login is not a member record that happens to be restricted.
- That separation is also why client seats stay free: only members count against the plan.
- Visibility scoping on tasks, comments and files
- The portal shows only tasks marked client-visible or client-editable, and only comments marked client-visible. “Preview as Client” applies that same rule rather than a separate mock.
- What you preview is what they get, so the check takes one click instead of a second login.
- Calendar tokens are encrypted at rest
- Google Calendar OAuth tokens are stored with Fernet symmetric encryption, not in plaintext.
- Connecting a calendar does not leave a reusable credential sitting in the database.
- GDPR export
- An async export job that produces a download link with a 24-hour time to live.
- A data request is a job you run, not a ticket you file with us.
If a refusal above is the dealbreaker
Then this is the wrong tool for that account, and that is a straight answer. It costs both of us less than finding out in week three of an onboarding. If your client's review will not approve a tool without SAML, buy something that has it.
So what: when a client's procurement form asks, the answer is on this page either way.
Read the list of what we do not have before you read the rest.