Security & Deployment

Designed to sit above your systems, securely

ConstraintFlow deploys into your environment and works with the data you already trust it with. This page describes our security and deployment approach and is explicit about what is available today, what is customer-configurable, and what is planned. We do not imply certifications we have not earned.

Available today

Capabilities in the platform today

Deployment options

Cloud-native deployment into the customer's preferred cloud or enterprise environment.

Customer environment isolation

Each customer deployment runs in its own isolated environment; data is not commingled across customers.

Encryption in transit

All traffic to and within the platform is encrypted using TLS.

Encryption at rest

Operational data is encrypted at rest using the underlying cloud provider's managed encryption.

Human approval controls

High-impact recommendations require human approval before they can be acted on; approval thresholds are configurable.

Auditability

Recommendations, approvals, and changes are recorded so decisions can be reviewed after the fact.

Secrets management

Credentials and connection secrets are stored using managed secret storage, never in application code.

Logging & observability

Application and access logs support operational monitoring and troubleshooting.

Data ownership

Customers own their operational data. ConstraintFlow processes it to deliver the service and does not sell it.

Customer-configurable

Configured with your team during deployment

Identity & access management

Authentication integrates with the customer's identity provider (SSO) during deployment.

Role-based access control

Access to data and actions is scoped by role so users only see and do what their role permits.

Model governance

Controls over how AI agents are grounded, what tools they may call, and which decisions they may influence.

Backup & recovery

Backup and recovery of operational data using the underlying platform's managed capabilities.

Licensing

Enterprise licensing scoped to plants, users, and capabilities; defined during procurement.

Planned

On the roadmap

Formal compliance certifications

Independent security certifications (e.g., SOC 2) are on the roadmap and will be published only once earned.

Data & AI governance

Humans stay in control of consequential decisions

ConstraintFlow does not autonomously execute high-impact production decisions. AI agents ground their reasoning in your operational model, call deterministic optimization tools, and propose explainable options. Configurable approval controls decide which recommendations can be automated and which require a person to review and commit them.

Reviewing ConstraintFlow with your security team?

We're glad to walk through deployment, isolation, and governance in detail.