Skip to main content
EN/FR interface · every recommendation checked against your business rules

Security

Security controls you can inspect.

See how Mongeflow isolates organizations, controls access, protects integrations, records administrative actions and handles operational incidents — and where to write when something looks wrong.

Five straight answers

Data isolation

Every record is scoped to your organization. Isolation is enforced at the database layer with row-level security — not just in application code — so one tenant's data cannot be read from another's session.

Access and authentication

Sign-in runs through our auth provider, with SSO available and role-based access inside each organization — who can view, review, or act on a decision is a role, not a habit.

Infrastructure

Mongeflow runs on managed cloud infrastructure with traffic encrypted in transit. SOC 2 Type II certification is held by our infrastructure providers; Mongeflow does not claim a certification of its own.

Verification culture

A suite of checks runs against the live product every morning, and a recommendation is marked verified only when every check on it passes. Reliability here is a routine, not a launch-week event.

Responsible disclosure

Found something that looks wrong? Report it through the contact page — a person reads every report, and we reply within one business day.

Report a security issue

Anything not listed here, we have not claimed. If a question matters to your review and this page does not answer it, ask — you will get the real answer, including when the real answer is "not yet".

Ask us the hard questions.

Security reviews get a reply from the team within one business day.