Security & Deployment

Designed to sit above your systems, securely

ConstraintFlow deploys into your environment and works with the data you already trust it with. This page describes our security and deployment approach. Every capability is configured with your team during deployment, mapped to your environment and policies.

Security & deployment approach

How ConstraintFlow protects the operation

Deployment options

Cloud-native deployment into the customer's preferred cloud or enterprise environment.

Customer environment isolation

Each customer deployment runs in its own isolated environment; data is not commingled across customers.

Encryption in transit

All traffic to and within the platform is encrypted using TLS.

Encryption at rest

Operational data is encrypted at rest using the underlying cloud provider's managed encryption.

Identity & access management

Authentication integrates with the customer's identity provider (SSO) during deployment.

Role-based access control

Access to data and actions is scoped by role so users only see and do what their role permits.

Human approval controls

High-impact recommendations require human approval before they can be acted on; approval thresholds are configurable.

Auditability

Recommendations, approvals, and changes are recorded so decisions can be reviewed after the fact.

Secrets management

Credentials and connection secrets are stored using managed secret storage, never in application code.

Logging & observability

Application and access logs support operational monitoring and troubleshooting.

Data ownership

Customers own their operational data. ConstraintFlow processes it to deliver the service and does not sell it.

Model governance

Controls over how AI agents are grounded, what tools they may call, and which decisions they may influence.

Backup & recovery

Backup and recovery of operational data using the underlying platform's managed capabilities.

Formal compliance certifications

Independent security certifications (e.g., SOC 2) will be published only once earned — we do not imply certifications we have not achieved.

Data & AI governance

Humans stay in control of consequential decisions

ConstraintFlow does not autonomously execute high-impact production decisions. AI agents ground their reasoning in your operational model, call deterministic optimization tools, and propose explainable options. Configurable approval controls decide which recommendations can be automated and which require a person to review and commit them.

Reviewing ConstraintFlow with your security team?

We're glad to walk through deployment, isolation, and governance in detail.