SECURITY & TRUST

Built to do the work.
Built to earn the access.

Operational execution requires more than a clever model. AmazFlow is designed around constrained authority, customer control, verifiable outcomes, and clear accountability.

Least privilege

Users, agents, and workflow steps receive only the access required for their authorized function.

Tenant isolation

Customer-scoped entities and requests are separated and enforced server-side.

Execution controls

Allowlisted actions, short-lived tasks, approvals, expiration, verification, retries, and revocation.

Encryption and secrets

Encryption in transit and at rest with managed secret references rather than embedded credentials.

Audit history

Material workflow actions record actor, method, policy, timing, result, and approval context.

Secure delivery

Infrastructure as code, testing, code review, dependency scanning, and vulnerability remediation.

AI governance

Structured outputs, bounded choices, confidence thresholds, policy enforcement, and human oversight.

Regulated data

BAA-supported deployment options are available for eligible HIPAA-regulated workflows.

Where AmazFlow stands today.

AmazFlow is building toward SOC 2 readiness but does not currently claim a SOC 2 examination. We do not make blanket “HIPAA compliant” claims. For eligible customer deployments, AmazFlow is prepared to evaluate and execute appropriate BAAs and restrict regulated data to approved architecture and subprocessors.

Security inquiries and responsible disclosures can be sent to security@amazflow.com. Privacy requests can be sent to privacy@amazflow.com.