Security

Your content system should be trustworthy as well as useful.

LinkFlows is designed around authenticated integrations, protected credentials, secure payment processing, and clear control over the data you connect.

Security overview

Clear controls, clear boundaries.

The controls below describe how the product is designed and operated today. They are a practical overview, not a promise of zero risk or a substitute for a customer-specific security review.

At a glance

  • OAuth tokens stay on the server.
  • Stripe processes full payment-card data.
  • Connected accounts can be disconnected.
  • No certification claim is made here.

Transport

Encrypted connections

Browser sessions and API traffic use HTTPS/TLS connections. Authentication is handled through protected application routes.

Credentials

Protected integration access

OAuth tokens and integration credentials are kept server-side, encrypted at rest, and excluded from frontend responses.

Payments

Stripe handles card data

Payment details are processed by Stripe. LinkFlows keeps the subscription and billing metadata needed to operate your account.

Access

Least-privilege workflows

Workspace permissions and integration scopes are intended to provide only the access needed for the selected workflow.

Operations

Traceable publishing activity

Sensitive workflow events such as publishing and token refreshes are logged to support troubleshooting and investigation.

Control

Disconnect and delete

You can disconnect integrations and request account or data deletion using the controls and process described in the Privacy Policy.

Integration lifecycle

You stay in control of connected accounts.

01

Connect

Authorize only the platform and permissions needed for the workflow you choose.

02

Operate

LinkFlows uses the connection to schedule, publish, sync, or measure the work you requested.

03

Disconnect

Remove the connection in LinkFlows, revoke it at the platform, or request deletion when you leave.

Read the Privacy Policy for data categories, retention, deletion requests, and third-party processors. See the Cookie Policy for browser storage and analytics choices.

Security questions

Answers for your review.

Does LinkFlows store my full payment-card number?

No. Checkout and payment-card processing are handled by Stripe. LinkFlows stores subscription and billing metadata needed to show your plan and operate billing.

Can I revoke a connected platform?

Yes. Disconnect an integration from LinkFlows and, where applicable, revoke the authorization from the connected platform as well. The Privacy Policy describes the related data-deletion process.

How should I report a security issue?

Email support@linkflows.com with the subject “Security question”. Do not include passwords, access tokens, API keys, or other secrets. Include the affected workflow and a safe reproduction summary instead.

Is LinkFlows SOC 2 or ISO 27001 certified?

This page describes product and operational controls; it is not a SOC 2, ISO 27001, or other certification statement. Contact support for the current security information relevant to your review.

For a security question or responsible disclosure, email support@linkflows.com.

Need details for your security review?

Tell us which workflow, integration, or data category you are evaluating and we will point you to the relevant controls.

Start for free