Your Data Stays In Your Control
FlowForma is built natively on Microsoft 365, so your process data, documents and workflow information never leave your own Microsoft tenancy. ISO 27001 certified, Cyber Essentials accredited, and built for enterprise governance from day one.
Independently Verified Security Standards
We hold ourselves to recognized, externally audited standards, not just our own word.
ISO 27001
Certified information security management system, independently audited.
Cyber Essentials
UK government-backed accreditation for core cyber security controls.
GDPR Compliant
Full alignment with global data protection and security frameworks.
M365 Native
Built inside your tenant, governed by your existing Microsoft controls.
How Does FlowForma Keep Your Data In Your Control?
Many workflow vendors are multi-tenant SaaS platforms, where your process data, documents and workflow information sit inside their cloud environment. FlowForma is different. Our workflow, forms and rules engine runs alongside Microsoft 365, so your process data and documents stay inside your own SharePoint environment, governed by your existing identity and access controls, rather than moving into a separate FlowForma-hosted database.
- No separate customer database holding your business process data
- No requirement to migrate documents into a third-party repository
- Identity and access managed through Microsoft Entra ID
- Your existing Microsoft governance policies apply automatically
At A Glance
- Where documents live
- Your Microsoft 365 tenant
- Identity provider
- Microsoft Entra ID
- Governance policies
- Yours, unchanged
- Data residency
- Set by your Microsoft tenant
FlowForma integrates with your existing Microsoft identity and access management framework, allowing organizations to maintain centralized control over authentication and user access.
A Security-First Culture
Ongoing training and strict access controls keep security embedded in how our team works.
Employee Security Training
Comprehensive, ongoing training keeps our team informed about the latest threats and best practices.
Phishing Awareness Campaigns
Simulated phishing tests are run regularly to reinforce vigilance and readiness against social engineering.
Role-Based Access Control
Access to sensitive data is strictly limited to authorized personnel based on their role, minimizing insider risk.
Have Specific Security or Compliance Requirements?
Talk to our team about how FlowForma fits your governance, data residency and audit needs.
Evolving As Fast As The Threat Landscape
Our security team continually evaluates and enhances our policies, processes and tools.
Independent Penetration Testing
We partner with reputable security firms to run regular internal and external penetration tests.
Third-Party Vendor Review
Every third-party app and provider is reviewed against our security and data protection standards before use.
Real-Time Incident Response
A formal incident response plan and dedicated team are ready to act immediately to mitigate risk.
Disaster Recovery & Business Continuity
Detailed recovery plans are tested through regular simulations, ensuring resilience and rapid restoration.
Regular Vulnerability Scanning
Automated scans across our infrastructure catch exploitable weaknesses, with prompt remediation.
Formal Security Policies
Documented security policies and incident response plans, backed by thorough background checks and staff training.
AI You Can Trust With Your Data
FlowForma Copilot runs on Microsoft's secure implementation of OpenAI. Your prompts, diagrams and uploaded documents are never shared with other customers, and are never used by OpenAI, Azure Direct Model providers, or any third party to train or improve AI models without your permission.
- Uploaded documents are never stored or used beyond your session
- Prompts are stored only so you can revisit and reuse them, and can be deleted anytime
- AI agent actions flow into your insights dashboard for full audit visibility
- Agents work inside your existing processes, measured the same way your team is
FlowForma Copilot
- Runs on
- Microsoft's secure OpenAI service
- Shared with other customers
- Never
- Used to train AI models
- Never, without permission
- Uploaded documents
- Not stored beyond your session
- Saved prompts
- Deletable by you, any time
Security Questions, Answered
Where is our business data stored when we use FlowForma?
Because FlowForma runs natively on Microsoft 365, all business data stays within your own tenant and is governed by your existing Microsoft security, compliance, and data residency controls. Your data stays exactly where it is today, inside your Microsoft 365 environment, with FlowForma simply orchestrating the process around it.
What certifications does FlowForma hold?
FlowForma is ISO 27001 certified, an internationally recognized standard for information security management, and holds Cyber Essentials accreditation, a UK government-backed certification for core cyber security controls. Both are independently audited on an ongoing basis.
Does FlowForma test its own security, and how often?
Yes. We partner with reputable third-party security firms to run regular internal and external penetration tests, alongside automated vulnerability scanning across our infrastructure. Any issues identified are remediated promptly, and every third-party app or provider we use is reviewed against our security and data protection standards before adoption.
What happens if FlowForma experiences a security incident?
We maintain formal security policies and a documented incident response plan. Our incident response team is prepared to act immediately to mitigate risk, and we maintain detailed disaster recovery and business continuity plans, tested through regular simulations, to ensure rapid restoration.
How do you track what an AI agent has done or suggested, for audit purposes?
When agents sit inside a structured process, they work like an assistant would, subject to the same measurement as any team member. You can see the inputs they received, the outputs they produced, and how they performed. All of that flows into your insights dashboard, so you can monitor what they're doing, how well they're performing, and how much work they're handling.
When I use FlowForma Copilot, how secure are the prompts and diagrams I enter?
FlowForma Copilot runs on Microsoft's secure implementation of OpenAI. Your prompts, diagrams, and uploaded documents:
- Are not shared with other customers
- Are not used by OpenAI, Azure Direct Model providers, or third parties to train or improve AI models
- Are never used to train any generative AI model without your permission
Uploaded documents are never stored or used beyond your session. Prompts are stored only so you can revisit and reuse them, and you can delete them at any time.
Is FlowForma GDPR compliant?
Yes. Because FlowForma stores customer data within your own Microsoft 365 tenant, organizations retain control over data residency, retention policies, access controls and compliance with GDPR and other applicable regulations.
Does FlowForma support role-based permissions?
Yes. FlowForma uses Microsoft 365 identity and security, allowing organisations to manage user permissions through Microsoft Entra ID, SharePoint permissions and role-based access controls to ensure users only access the information appropriate to their role.
Automate With Confidence
See how FlowForma keeps your process data, documents and identity under your control, while your team automates faster.
