UniFlow DeskBack to the launch site
SECURITY & TRUST

The safest assistant is one that knows what it must never do.

Current security posture: July 29, 2026

Plain-language policy

This page describes current UniFlow Desk practices. It is not a claim of certification, and it does not reduce any mandatory rights under applicable law.

Permission boundary

01Observe

Read only what the provider and user explicitly authorize.

02Explain

Show the evidence, reason, confidence, and original source.

03Ask first

Keep drafts unsent and high-impact decisions with the user.

UniFlow Desk does not request Gmail modify access or Microsoft read-write mail access. It does not send, edit, delete, archive, or mark messages as read. It never follows a payment link or acts on instructions found inside a message.

Implemented controls

Provider access

OAuth or provider-issued credentials with the smallest supported read scope; no mailbox passwords for Gmail or Microsoft.

Encryption

TLS in transit plus encrypted provider tokens, normalized messages, signals, drafts, control state, and portable backups.

Tenant isolation

Workspace-scoped records, roles, invitations, authorization checks, and tenant-keyed message and signal storage.

Account protection

Scrypt password hashing, expiring opaque sessions, email verification, authenticator-app MFA, and single-use recovery codes.

Auditability

Bounded hash-chained security activity, privacy-limited product activity records, optional signed audit export, source evidence, and provider connection health.

Reliability

Persist-before-acknowledge webhooks, idempotency, retry backoff, dead-letter health, reconciliation, and backup/restore verification.

Untrusted-content boundary

  • Message text and attachments are treated as untrusted input.
  • The extraction model receives no provider token, password, encryption key, recovery code, or external action tool.
  • Attachments are detected but are not downloaded during the current service stage.
  • Extracted links are not followed during classification.
  • AI evidence must occur in the source message and pass strict structured validation.
  • Users are directed back to the original provider before financial, legal, or security action.

Connector truth table

SourceModeImportant limitation
Gmail and OutlookRead-onlyBounded backfill and authorized mailbox events.
Slack and TeamsScopedOnly eligible conversations permitted by the provider and organization.
Regional emailRead-only IMAPDirect TLS and approved public hosts; provider app passwords may be required.
WhatsApp BusinessInbound webhookApproved Business Cloud API numbers only.
TelegramBot modeOnly updates delivered to the authorized bot.

Control and compliance map

Framework names below describe the engineering and governance baselines used to design and review the service. They are not badges and do not mean UniFlow Desk has received an independent certification or attestation.

GDPR and UK GDPR readiness

Data minimization, purpose and lawful-basis mapping, processor controls, rights workflows, retention, deletion, and transfer safeguards.

ePrivacy and PECR principles

No advertising trackers; necessary storage only unless a future optional technology is disclosed and valid consent is obtained.

OWASP ASVS and Top 10 baseline

Authorization, input validation, session protection, secret isolation, rate limits, logging, dependency hygiene, and untrusted-message boundaries.

NIST CSF 2.0 mapping

Govern, identify, protect, detect, respond, and recover activities connected to owners, evidence, review cadence, and release gates.

CIS Controls v8 mapping

Inventory, access control, secure configuration, data protection, audit logs, vulnerability handling, backups, and incident response.

WCAG 2.2 Level AA target

Keyboard operation, visible focus, semantic structure, responsive reflow, reduced motion, labels, feedback, and accessible alternatives.

Ongoing operational readiness

Operational reviews include restore drills, tenant-isolation tests, secret-rotation tests, webhook replay tests, connector-expiry alerts, incident-contact checks, and subprocessor and data-location reviews. These controls are reviewed as the service and its provider access change.

Current assurance status

UniFlow Desk does not currently claim SOC 2, ISO 27001, Google CASA, PCI DSS, HIPAA, or another independent certification unless a signed customer document states otherwise. Provider verification and customer security review are separate from product implementation.

Responsible disclosure

Report a suspected vulnerability through the contact form. Include the affected URL or feature, reproducible steps, impact, and a safe contact method. Do not access another person's data, degrade availability, use social engineering, or publicly disclose an unresolved issue. We will acknowledge valid reports and coordinate remediation in good faith.

Privacy and providers

See the privacy notice for legal bases and rights, and the subprocessors page for current hosting and optional processing providers.

© 2026 UniFlow Desk
PrivacyTermsCookiesSecuritySubprocessorsLegal noticeData deletionAccessibility