Encrypted everywhere
Data is encrypted in transit and at rest, with keys rotated automatically and isolated per workspace.
- TLS 1.3 for every connection, HSTS enforced
- AES-256 encryption at rest
- Per-workspace key isolation with automatic rotation
- Secrets stored in a managed vault, never in application code
Permissions you already trust
Loreflow is designed to mirror the access rules of every source it reads. If someone cannot open a document in the source tool, it should not exist for them in Loreflow.
- Per-source scoping by channel, folder, project or workspace
- Source permissions re-synced on every crawl
- Role-based access inside the workspace, including read-only investors
- Granular investor access levels: reports only, reports plus metrics, or full read access
We store the connective layer,
not your files
Original content stays in the source tool. Loreflow keeps references, relationships and summaries, and fetches the original on demand with the viewer's own permissions.
- No shadow copy of your document library
- Deletion in the source propagates to Loreflow
- Full workspace export and hard delete on request
Operational safeguards
Access to production is limited, logged and reviewed. Every administrative action inside a workspace is recorded.
- SSO and SCIM provisioning on Enterprise
- Immutable audit log of access, exports and permission changes
- Least-privilege production access with mandatory review
- Regional data residency options (US, EU)
Compliance posture
Loreflow runs a SOC 2 Type II program and supports GDPR obligations including DPAs and subprocessor disclosure. Certification status, current subprocessor list and penetration test summaries are shared under NDA on request — ask us rather than assuming a status from this page.
Report a vulnerability
Send findings to security@loreflow.example. We acknowledge reports within one business day and will keep you updated through remediation.