Security FirstZero Trust Architecture
Pubflow is built on Zero Trust principles. Every request is verified, every secret is protected, and every system is audited.
What is Zero Trust?
Never trust, always verify. Every request is authenticated and authorized.
Flowless Authentication Security
Industry-leading password security and session management
Passwords Are Never Stored in Plain Text
Flowless never stores passwords in plain text or reversible encryption. All passwords are hashed with Argon2id before being stored. Even Pubflow staff cannot access user passwords.
Enterprise Secrets Management
Database credentials and sensitive data protected with Azure Key Vault
Azure Key Vault Integration
Enterprise-grade secrets management
What secrets are protected?
Sensitive Tag Protection
All secrets marked as critical are:
- βEncrypted at rest in Azure Key Vault with FIPS 140-2 Level 2 validated HSMs
- βEncrypted in transit with TLS 1.3
- βFully audited with Azure Monitor and logging
- βAccess controlled with RBAC and managed identities
- βAutomatically rotated based on security policies
Complete Audit Trail
Every access to sensitive secrets is logged and monitored:
- β’Who accessed the secret (service identity)
- β’When the access occurred (timestamp with timezone)
- β’What operation was performed (read, write, delete)
- β’Where the request came from (IP address and region)
Responsible Security Disclosure
We take security seriously and appreciate the security research community
Report a Security Vulnerability
If you've discovered a security vulnerability in Pubflow, Flowless, Flowfull, or any of our products, please report it to:
What to include in your report:
- 1.Description of the vulnerability and its potential impact
- 2.Steps to reproduce the issue (proof of concept)
- 3.Affected components (Flowless, Flowfull, Bridge Payments, etc.)
- 4.Your contact information for follow-up
- 5.Any suggested fixes or mitigations (optional)
Our Commitment:
- βWe will respond to your report within 24 hours
- βWe will keep you updated on our progress
- βWe will credit you in our security advisories (unless you prefer to remain anonymous)
- βWe will not take legal action against security researchers acting in good faith
Security Patches & Suggestions:
For general security suggestions, configuration improvements, or non-critical security patches, please also email security@pubflow.com. We review all suggestions and implement improvements regularly.
Build with confidence
Start building secure applications with Pubflow's Zero Trust architecture