Least privilege
Users, agents, and workflow steps receive only the access required for their authorized function.
Operational execution requires more than a clever model. AmazFlow is designed around constrained authority, customer control, verifiable outcomes, and clear accountability.
Users, agents, and workflow steps receive only the access required for their authorized function.
Customer-scoped entities and requests are separated and enforced server-side.
Allowlisted actions, short-lived tasks, approvals, expiration, verification, retries, and revocation.
Encryption in transit and at rest with managed secret references rather than embedded credentials.
Material workflow actions record actor, method, policy, timing, result, and approval context.
Infrastructure as code, testing, code review, dependency scanning, and vulnerability remediation.
Structured outputs, bounded choices, confidence thresholds, policy enforcement, and human oversight.
BAA-supported deployment options are available for eligible HIPAA-regulated workflows.
AmazFlow is building toward SOC 2 readiness but does not currently claim a SOC 2 examination. We do not make blanket “HIPAA compliant” claims. For eligible customer deployments, AmazFlow is prepared to evaluate and execute appropriate BAAs and restrict regulated data to approved architecture and subprocessors.
Security inquiries and responsible disclosures can be sent to security@amazflow.com. Privacy requests can be sent to privacy@amazflow.com.