Trust & Security
How TumiFlow is being built
TumiFlow is in active development. The controls below are planned, not yet complete, and this page will be updated as each one ships.
Privacy-first design
TumiFlow is being built so customer data is used only for the purpose it was given, not sold or used to train shared models.
Workspace isolation
TumiFlow is being designed with workspace-level data isolation.
Role-based permissions
Role-based access controls are part of the production architecture, so each role sees only what it requires.
Encrypted provider credentials
Production plans include encrypted storage for connected provider credentials.
Audit logs
Planned audit controls will record sensitive account actions.
Data export & deletion
Data export and deletion tools are planned for production.
AI permissions
AI permission controls are being designed to give workspace owners control over automated actions.
Consent & retention controls
Production implementation will include consent capture, retention settings and regional data preferences.
No third-party security certification is currently claimed. TumiFlow does not hold SOC 2, ISO, HIPAA or GDPR certification and has not completed a formal security audit. Nothing on this page should be read as a claim that a control is already in place.
When a control is implemented, or a certification or audit is completed, it will be named and dated here.