Security
Security controls you can inspect.
See how Mongeflow isolates organizations, controls access, protects integrations, records administrative actions and handles operational incidents — and where to write when something looks wrong.
Five straight answers
Data isolation
Every record is scoped to your organization. Isolation is enforced at the database layer with row-level security — not just in application code — so one tenant's data cannot be read from another's session.
Access and authentication
Sign-in runs through our auth provider, with SSO available and role-based access inside each organization — who can view, review, or act on a decision is a role, not a habit.
Infrastructure
Mongeflow runs on managed cloud infrastructure with traffic encrypted in transit. SOC 2 Type II certification is held by our infrastructure providers; Mongeflow does not claim a certification of its own.
Verification culture
A suite of checks runs against the live product every morning, and a recommendation is marked verified only when every check on it passes. Reliability here is a routine, not a launch-week event.
Responsible disclosure
Found something that looks wrong? Report it through the contact page — a person reads every report, and we reply within one business day.
Anything not listed here, we have not claimed. If a question matters to your review and this page does not answer it, ask — you will get the real answer, including when the real answer is "not yet".
Ask us the hard questions.
Security reviews get a reply from the team within one business day.