Trust Center

Workload data stays on the nodes you attach.

dFlow Cloud is the control plane at app.dflow.sh. This page is the evidence packet for DPA, GDPR, subprocessors, and incident contact.

  • GDPRAvailable
  • DPAOn request
  • SOC 2 Type IIn progress
Custody · data path
Inspect a plane

On this plane

Stays on those nodes

1 data category on this plane.

  • Customer content

    Connected Git repositories, container images, and database data on your nodes

    Customer-controlled workload data

Architecture, security, and operations documentation lives at docs.dflow.shOpens in a new tab.

02 · security

Security program

These practices cover the dFlow control plane and the product surfaces that reach your Worker Nodes.

01

Access management

Organisation membership uses role-based permissions. Teams can define custom roles with plan limits, and sign-in supports email and password with optional magic link or GitHub OAuth. Enterprise workspaces can use SAML or OIDC single sign-on (SSO) when it is enabled for the organisation.

02

Infrastructure and network

Worker Node management uses SSH. Azure has a native account integration, including security groups. AWS, Google Cloud, DigitalOcean, and Hetzner can be attached as manual Worker Nodes. Tailscale is used for private connectivity between the control plane and nodes.

03

Monitoring and availability

Operational status is published at status.dflow.sh. Worker Nodes can use Beszel and Netdata when those tools are installed, and service logs and deployment history are available in the product.

04

Application security

Public application traffic is routed through the platform proxy with TLS. Sign-in flows can use Cloudflare Turnstile when enabled.

Product controls

Controls you can map to access reviews, change management, and backup planning.

01

Tenant isolation

Applications, servers, integrations, SSH keys, security groups, billing, and team membership are scoped to an Organisation.

02

Secrets and configuration

Environment variables and service configuration are stored in the control plane. Git, registry, and cloud integration credentials follow organisation permissions.

03

Data protection

Database services support backups and restore flows in the product. Those backups cover database services you configure in dFlow and are not a substitute for your own disaster-recovery planning.

04

Operational visibility

Deployments, builds, service logs, and infrastructure actions are visible in the dashboard. Some records include the member who triggered the change.

03 · privacy

Compliance

Formal attestations apply to the surfaces dFlow operates. Customer cloud accounts and workload design remain your responsibility unless a signed agreement says otherwise.

Attestations
In progress

SOC 2 Type I

In progress

Formal attestation for the dFlow Cloud control plane is in progress.

Privacy PolicyCookie PolicyTerms of Service

Subprocessors

Vendors dFlow uses to operate dFlow Cloud, the marketing site, and shared platform services.

Vendors · platform
Hetzner

Cloud and dedicated servers for managed Worker Node capacity offered through dFlow Cloud.

Subprocessors for dFlow and related services. Questions about this list or data processing? Email [email protected].

04 · requests

Resources

Policies, architecture references, and procurement entry points.

Frequently asked questions

Short answers for security, privacy, and procurement reviews.

Privacy or security questions? Email [email protected].

Updates

Follow product changes and operational notices outside this page.