Flowvenue · Security & Compliance

Flowvenue Security, Compliance & Certifications

Flowvenue is an enterprise Agentic Business Process Platform with certified ISO 9001 quality management and a certified Information Security Management System under ISO/IEC 27001, including certified ISO/IEC 27017 and ISO/IEC 27018 extensions, qualified ACN Level 1, and subject to independent vulnerability assessment and penetration testing. Production workloads run on AWS in the Milan (eu-south-1) region in the European Union. This page provides an overview of Flowvenue's information security, data protection, cloud security, AI/data governance and compliance framework.

Certifications and qualifications

Compliance Overview

Last updated: September 2026 Version: 2026.09


Flowvenue compliance at a glance

Area Public posture
Quality management ISO 9001 — certified quality management system (QMS)
Information security ISO/IEC 27001 — certified Information Security Management System (ISMS)
Cloud security ISO/IEC 27017 — certified extension for cloud services
PII protection in public cloud ISO/IEC 27018 — certified extension for PII in public cloud
Italian cloud qualification (ACN) ACN Level 1 — Flowvenue is qualified at ACN Level 1; public compliance materials also support ACN / PA questionnaires (security measures, NIST SP 800-145 mapping, verification evidence)
Security assurance Independent vulnerability assessment and penetration testing (VA/PT) by an external provider

Certificate extracts, scope statements and formal packs are available under Verification & Evidence.


Our Commitment to Compliance

Beyond technological innovation, Flowvenue considers regulatory compliance and information security fundamental elements of our platform. We are committed to transparency, security, and compliance with applicable data protection and information security regulations. This public compliance section provides information about our approach to:

  • Quality managementCertified ISO 9001 quality management system (QMS), covering development and delivery of the Flowvenue technology platform (see Verification & Evidence)
  • GDPR & ePrivacy Compliance - Consent management, cookie policies, and data protection
  • Information SecurityCertified ISO/IEC 27001 ISMS, with ISO/IEC 27017 (cloud services) and ISO/IEC 27018 (PII in public cloud) as certified extensions within scope (details)
  • AI / LLM governance — Platform-managed models (default OpenAI GPT-5.6 Luna; Anthropic where enabled), Customer model selection, Bring Your Own Key (BYOK), and external LLM clients via MCP Server — shared-responsibility and sub-processor boundaries (Information Security — AI/LLM, Security measures — §1.5)
  • Operational continuity & IT service management - Internal procedures and the Service management & ITIL 4 overview (aligned with good practices for continuity and service delivery), cross-linked from Information Security. Accredited information-security certification in this public section is ISO/IEC 27001 / 27017 / 27018 for the ISMS; ISO 9001 is a separate quality certification
  • Accountability - Demonstrable compliance through documented processes
  • Interoperability (AgID framework & REST/OpenAPI profile) - Public statement of alignment with Italy’s digital administration and AgID interoperability model for REST APIs, with machine-readable OpenAPI 3 documentation where applicable (see dedicated page)
  • Cloud service characteristics (NIST SP 800-145) - Public mapping of our SaaS on AWS (including autoscaling) to the essential cloud characteristics often cited in procurement and security reviews—self-service provisioning, network access (including public Internet / HTTPS), and elasticity—with a clear shared responsibility split (see dedicated page)

Public administration, ACN Level 1, cloud qualification, and enterprise questionnaires: Flowvenue is qualified at ACN Level 1. This site publishes versioned statements (quality management ISO 9001, information security certification ISO/IEC 27001 / 27017 / 27018, VA/PT cadence, AgID / REST–OpenAPI posture, NIST cloud characteristics, ITIL-based service management transparency) to support due diligence and structured questionnaires, including ACN / Italian public-administration materials, without publishing operational secrets. Descriptive material on continuity and service operations does not extend accredited ISMS certification beyond the ISMS scope stated on the certificate. Contractual metrics (SLA, penalties, insurance, bespoke monitoring, export/reversibility, support hours) and signed attestations are not fully predetermined here: they are set in the agreement with each contracting body or provided on formal request as described in Verification & Evidence and in Contractual negotiation with the client below.


Why We Publish This Information

Transparency

We believe that transparency builds trust. By making our compliance approach publicly available, we enable:

  • Users to understand how their data is protected and how consent is managed
  • Enterprise clients to evaluate our security and compliance posture
  • Auditors and regulators to assess our commitment to compliance

Accountability

Under GDPR Article 5(2), we are accountable for demonstrating compliance. This public documentation:

  • Shows our commitment to privacy-by-design and security-by-design principles
  • Describes our compliance framework and verification methods
  • Enables stakeholders to verify our practices

Security-by-Design

Security and privacy are not afterthoughts—they are fundamental to how we build and operate Flowvenue. Our compliance framework reflects this commitment.


Scope of Public Documentation

This public compliance section includes:

✅ What You Will Find

  • Cookie Policy - Complete information about cookies and tracking technologies
  • Consent Management - How we collect, manage, and respect user consent
  • Security Framework - High-level overview of our information security management approach
  • Security measures & supplier requirements - Structured controls (Italian), including periodic VA/PT (external report; roadmap April / August / December, max. four-month gap) and a summary of AWS infrastructure dependency (VPC, ECS, RDS, etc.); for NIST SP 800-145-style checklists (self-service, network access, elasticity), see the dedicated cloud characteristics page
  • VA/PT evidence - Published summaries and report links plus the /compliance/reports/ folder for PDFs when released
  • Compliance Principles - Our commitment to GDPR, ePrivacy, and certified ISO/IEC 27001 / 27017 / 27018 (see Information Security)
  • Continuity & service management (ITIL alignment) - Published procedures and Service management & ITIL 4 describe how we run service lifecycle activities; this is descriptive transparency and does not add certifications beyond Information Security — certified standards (ISO/IEC 27001 / 27017 / 27018). See also Verification & Evidence

❌ What Is Not Included

This public documentation does not include:

  • Internal operational procedures (except procedure pages explicitly linked from this section, e.g. security assessment, backup, incident response)
  • Detailed technical runbooks, credentials, and configuration dumps
  • Full risk registers or raw internal-only technical annexes (client-facing VA/PT outcome PDFs are published under /compliance/reports/ for all customers; sanitization avoids disclosing exploitable detail)
  • Incident response plans
  • Asset inventories
  • Internal audit reports

Why? These documents contain sensitive information that could:

  • Reveal system architecture and attack surfaces
  • Expose specific risks or vulnerabilities
  • Compromise security measures
  • Violate confidentiality obligations

Access to Detailed Documentation

For Auditors and Regulators

Detailed compliance documentation, including:

  • Technical implementation details
  • Audit trails and evidence
  • Risk assessments and treatment plans
  • Internal procedures and controls

...is available upon formal request for:

  • Regulatory audits
  • Certification or conformity assessment processes (ISO/IEC 27001 / 27017 / 27018 — see Information Security); additional internal evidence on continuity and service operations can be shared under Verification & Evidence and Service management & ITIL 4, proportionate to the request
  • Enterprise client due diligence (under NDA)
  • Legal proceedings

Request Process

To request detailed compliance documentation:

  1. Identify your role and purpose:

    • Regulatory authority conducting an audit
    • Certification or conformity assessment body (e.g. ISO/IEC 27001 / 27017 / 27018 — certificate evidence via Information Security / Verification & Evidence); further continuity / service-management material is available as descriptive documentation and formal disclosure under Verification & Evidence, not as separate accredited certificates
    • Enterprise client evaluating Flowvenue (under NDA)
    • Legal representative in formal proceedings
  2. Contact us:

  3. Provide:

    • Official identification
    • Purpose of the request
    • Scope of documentation needed
    • Legal basis for the request (if applicable)

We will respond within reasonable timeframes and provide documentation appropriate to the request, subject to confidentiality and legal requirements.

Note: Flowvenue reserves the right to evaluate and limit access to documentation based on the legitimacy, proportionality, and applicability of the request.


Document Structure

This public compliance section is organized as follows:

  1. Cookie & Tracking Compliance
    Complete cookie policy, tracking technologies, and consent mechanisms

  2. GDPR & Consent Management
    How we collect, manage, and respect user consent in compliance with GDPR and ePrivacy

  3. Information Security (ISO/IEC 27001, 27017, 27018)
    Certified ISMS (ISO/IEC 27001) with ISO/IEC 27017 and ISO/IEC 27018 extensions; continuity and service operations are described separately under certified standards and Continuity and service operations

  4. Security measures and supplier requirements
    Structured overview of security measures and technical/organisational requirements we guarantee (with topic index for quick lookup)

  5. Identity Provider Integration Security Guidelines
    Security guidelines for integrating external Identity Providers (OIDC, OAuth 2.0, SAML 2.0) with the Flowvenue platform

  6. Interoperability & AgID model (REST / OpenAPI)
    Reference framework (CAD, AgID interoperability model, technical profile REST + OpenAPI 3); scope and limits vs contractual attestation

  7. Cloud service & NIST SP 800-145 characteristics (Italian)
    SaaS on AWS with autoscaling: declarative mapping for self-service provisioning, network access (HTTPS / Internet and contractual options), and elasticity; useful for public administration questionnaires and third-party reviews

  8. REST API catalog & OpenAPI
    Catalog of REST API mount points and companion OpenAPI 3 file is not published as a public static page. It is available only to authenticated Super User accounts via the in-app compliance route /compliance/api-documentation and authenticated endpoints GET /api/admin/compliance-api-docs/markdown and GET /api/admin/compliance-api-docs/openapi.yaml.

  9. Verification & Evidence
    How compliance can be verified, what evidence is available, and public VA/PT materials (Evidenze VA e PT · /compliance/reports/)

  10. Service management & ITIL 4
    How we structure product lifecycle and cloud service practices using ITIL 4 good practices; descriptive evidence map for auditors and clients; links to security, continuity, and procedures

Documentation updates: The information in this section can be updated and made available on an annual basis for the duration of the contract following a formal request by the client. Detailed supporting documentation is available upon formal request (see Verification & Evidence).

Contractual negotiation with the client

Several topics that often appear in public-administration or enterprise questionnaires (for example: SLA and service credits or penalties, insurance limits, dedicated monitoring or dashboards for the contracting body, SIEM log forwarding, incident notification windows and channels, data export / portability formats and schedules, reversibility at contract end, support hours and languages beyond the baseline described here) are not intended to be fully predetermined solely by this public website. Unless already fixed in a published DPA or general terms, such items are defined in writing in the contract, technical annexes, security schedules, or order-specific agreements with each client. This public documentation describes organisation, processes, and technical posture; quantitative commitments and bespoke channels follow from the signed agreement with that client.


Our Principles

Privacy by Design

We implement privacy protections from the ground up, not as an afterthought. User consent is collected before any non-essential tracking occurs.

Security by Design

Security is built into our systems, processes, and culture. We adopt a risk-based approach to information security management.

Transparency

We are transparent about our practices while protecting sensitive operational information.

Accountability

We can demonstrate compliance through documented processes, audit trails, and evidence.

Continuous Improvement

We regularly review and improve our compliance framework to adapt to:

  • Evolving regulations
  • Emerging threats
  • Best practices
  • Stakeholder feedback

Contact

Flowvenue currently operates with a small internal organisation; the same natural person may cover several statutory or operational roles until the team scales.

Area Channel
DPO, information security / ISMS, IRT / company CSIRT, technical security contact, internal escalation Marcello Riccimricci@flowvenue.com
Opening service incidents, security incident reports (initial triage), general support, compliance information requests Email: info@flowvenue.comWhatsApp: +39 350 998 6359 (voice/SMS-capable number used for the WhatsApp Business line)
PEC (formal notices, Italy) flowvenue@pecimprese.it

For formal verification packs and structured due diligence, follow Verification & Evidence.


Note: This is public documentation. Internal compliance documentation is available upon formal request for authorized parties.