Flows360 is designed to connect business systems, automate operational work and provide clear evidence that workflows completed as expected.
Security and compliance are delivered through a combination of Flows360 application controls and the independently certified infrastructure and platform controls provided by Lovable.
Independently certified infrastructure
Flows360 Studio is built and published using Lovable infrastructure.
Lovable maintains SOC 2 Type II and ISO 27001:2022 accreditations and provides GDPR-related data-processing protections.
Flows360 benefits from these underlying infrastructure and platform controls while applying its own controls across authentication, permissions, workflow execution, integrations and operational governance.
SOC 2 Type II · ISO 27001:2022
Infrastructure compliance provided by Lovable.
Lovable's certifications apply to Lovable and its audited control environment. Flows360 LTD does not represent itself as independently SOC 2 or ISO 27001 certified.
Flows360 application security evidence
Lovable provides a deployment-specific Trust Centre for the published Flows360 Studio application:
https://studio.flows360.app/.well-known/trust.html
At the latest verification on 2 September 2026, Lovable reported the following controls as checked or enabled for the published Flows360 Studio deployment:
- dependencies checked for known vulnerabilities;
- software inventory / SBOM created;
- published-version provenance recorded;
- health checks enabled;
- database access review enabled;
- row-level security checked on every reviewed table; and
- automatic security fixes enabled.
The Trust Centre is tied to the current published deployment and may be re-evaluated as the application changes.
Flows360 application controls
Depending on the service and deployment, Flows360 uses controls designed to support:
- authenticated access;
- role and tenant permissions;
- secure handling of credentials and secrets;
- controlled workflow execution;
- operational logging and traceability;
- environment and configuration controls;
- data separation;
- secure communications;
- incident response; and
- governance over integrations and automated actions.
Data protection
Where Flows360 processes personal data on behalf of a customer, our Data Processing Agreement applies.
Our current subprocessors are listed on our Subprocessors page.
International transfers, where applicable, are handled using appropriate contractual and legal safeguards.
Customer responsibilities
Customers remain responsible for controlling access to their Flows360 account, protecting credentials, configuring connected systems appropriately, determining which data should be processed, ensuring a lawful basis exists, reviewing workflows before production use where appropriate, and meeting any additional legal or regulatory requirements that apply to their organisation.
Sensitive and regulated data
Flows360 should not be assumed suitable for every category of regulated or highly sensitive information by default.
Customers planning to process patient data, protected health information or other specially regulated data should contact Flows360 before production use so that the proposed architecture, service plan and contractual requirements can be assessed.
Compliance evidence
Flows360 Studio application Trust Centre
https://studio.flows360.app/.well-known/trust.html
Lovable Trust Centre
https://trust.lovable.dev/
Lovable Security
https://lovable.dev/security
Lovable Data Processing Agreement
https://lovable.dev/data-processing-agreement
Contact
Questions about security, compliance or data protection can be sent to:
