Trust & Security

How TumiFlow is being built

TumiFlow is in active development. The controls below are planned, not yet complete, and this page will be updated as each one ships.

Privacy-first design

TumiFlow is being built so customer data is used only for the purpose it was given, not sold or used to train shared models.

Workspace isolation

TumiFlow is being designed with workspace-level data isolation.

Role-based permissions

Role-based access controls are part of the production architecture, so each role sees only what it requires.

Encrypted provider credentials

Production plans include encrypted storage for connected provider credentials.

Audit logs

Planned audit controls will record sensitive account actions.

Data export & deletion

Data export and deletion tools are planned for production.

AI permissions

AI permission controls are being designed to give workspace owners control over automated actions.

Consent & retention controls

Production implementation will include consent capture, retention settings and regional data preferences.

No third-party security certification is currently claimed. TumiFlow does not hold SOC 2, ISO, HIPAA or GDPR certification and has not completed a formal security audit. Nothing on this page should be read as a claim that a control is already in place.

When a control is implemented, or a certification or audit is completed, it will be named and dated here.