Data handling

Your code and screenshots stay inside your cloud. Where the data lives, who can see it, and how to check each claim yourself.

Last updated: July 28, 2026

1 · There is no new AI vendor in the path

FlowGuard scans your codebase and verifies screenshots with Claude — but the model does not run on the public Anthropic API. It runs on Pintor Project's private Azure AI Foundry deployment, inside the same Microsoft cloud that already hosts your FlowGuard tenant. Your code, screenshots and test data never leave that private boundary, and are never used to train a model.

ControlAI inference is served from a private Foundry endpoint in the same region as your tenant. No public inference, no cross-geography fallback. Enterprise customers may bring their own endpoint, in which case residency is governed entirely by that endpoint.

VerifyThe complete list of providers who process data on our behalf is public on the Sub-processors page — Anthropic appears there only as “accessed through the Provider's private Azure AI Foundry deployment.”

2 · Encryption, everywhere

Data is encrypted in transit and at rest, and the secrets you hand FlowGuard get a second envelope on top.

  • In transit: TLS 1.2+ everywhere — agent ↔ API, dashboard ↔ API, ticket-provider calls.
  • At rest: Azure SQL with TDE, plus application-level AES-256 envelope encryption for secret variables, integration PATs and tenant API keys.
  • Key custody: Data Encryption Keys live in Azure Key Vault, per tenant on Enterprise; rotation is automatic every 90 days.

VerifyThe full encryption posture is documented on the Security & Privacy docs page.

3 · Screenshots are private and redactable

Vision checkpoints capture screenshots. Those are the most sensitive artifact FlowGuard stores, so they get the strictest handling.

ControlScreenshots are stored in Azure Blob with private access only; signed URLs expire in 15 minutes. Mark sensitive selectors with mask on a Screenshot step and the region is redacted before the image is stored.

VerifyAdd a masked selector to any flow and inspect the stored screenshot — the region is blacked out in the artifact itself, not just the viewer.

4 · Isolation and residency

Tenants are isolated at the database level, and each region is an independent deployment — there is no cross-region replication by design.

ControlDatabase-per-tenant isolation. Each region runs its own catalog DB, tenant DBs and object storage inside the jurisdictional boundary. A request that lands on the wrong regional deployment receives an HTTP 421 Misdirected Request rather than being served — defense in depth even if DNS were misrouted.

VerifyEU (West Europe) residency is available on Business and Enterprise; UK and AU on Enterprise. Ask for a specific region in your Service Order — see Data residency.

5 · Personal data is excluded, not just protected

FlowGuard exercises your application's UI; it does not need your customers' real records to do it. The safest personal data is the data that never enters the system.

ControlYou choose the test data a flow uses. Use synthetic or masked fixtures for UAT, and mask any on-screen region that would render real personal data. FlowGuard has no need to ingest production PII to verify a checkout, a login or a dashboard.

VerifyReview your flows' input data and Screenshot steps — anything sensitive should be synthetic or masked. Our Acceptable Use and DPA set the contractual side of this.

6 · What is not yet true, stated plainly

We would rather under-claim than surprise you in a security review. Two things are in progress, not done:

  • SOC 2: controls are implemented (audit log, least-privilege roles, secret management, encryption, change tracking). A Type I readiness assessment with a third-party platform is scheduled. We do not claim certification until the report is in our hands.
  • Penetration testing:scheduled. Until the report exists, we don't say “pen-tested.”

VerifyThe full, hedged posture — including GDPR, ISO 27001 stance and self-hosting for the strictest cases — is on the Compliance page.

Where this fits

This page is the promise about your data. For our broader position on why a scoped, contracted AI path is no riskier than the tools already in your stack, read The code already left the building. Report a vulnerability any time to security@flowguardians.com.

Questions: legal@flowguardians.com

Pintor Project Co. — a Delaware corporation. FlowGuard is a product of Pintor Project Co.