Designed to sit above your systems, securely
ConstraintFlow deploys into your environment and works with the data you already trust it with. This page describes our security and deployment approach and is explicit about what is available today, what is customer-configurable, and what is planned. We do not imply certifications we have not earned.
Capabilities in the platform today
Deployment options
Cloud-native deployment into the customer's preferred cloud or enterprise environment.
Customer environment isolation
Each customer deployment runs in its own isolated environment; data is not commingled across customers.
Encryption in transit
All traffic to and within the platform is encrypted using TLS.
Encryption at rest
Operational data is encrypted at rest using the underlying cloud provider's managed encryption.
Human approval controls
High-impact recommendations require human approval before they can be acted on; approval thresholds are configurable.
Auditability
Recommendations, approvals, and changes are recorded so decisions can be reviewed after the fact.
Secrets management
Credentials and connection secrets are stored using managed secret storage, never in application code.
Logging & observability
Application and access logs support operational monitoring and troubleshooting.
Data ownership
Customers own their operational data. ConstraintFlow processes it to deliver the service and does not sell it.
Configured with your team during deployment
Identity & access management
Authentication integrates with the customer's identity provider (SSO) during deployment.
Role-based access control
Access to data and actions is scoped by role so users only see and do what their role permits.
Model governance
Controls over how AI agents are grounded, what tools they may call, and which decisions they may influence.
Backup & recovery
Backup and recovery of operational data using the underlying platform's managed capabilities.
Licensing
Enterprise licensing scoped to plants, users, and capabilities; defined during procurement.
On the roadmap
Formal compliance certifications
Independent security certifications (e.g., SOC 2) are on the roadmap and will be published only once earned.
Humans stay in control of consequential decisions
ConstraintFlow does not autonomously execute high-impact production decisions. AI agents ground their reasoning in your operational model, call deterministic optimization tools, and propose explainable options. Configurable approval controls decide which recommendations can be automated and which require a person to review and commit them.
Reviewing ConstraintFlow with your security team?
We're glad to walk through deployment, isolation, and governance in detail.