Information Security (ISO/IEC 27001, 27017, 27018)

Certified ISMS under ISO/IEC 27001 with ISO/IEC 27017 and ISO/IEC 27018 extensions; continuity and service operations described separately.

Last updated: June 2026 Version: 2026.06


Our Commitment to Information Security

Flowvenue operates an Information Security Management System (ISMS) that has been certified under ISO/IEC 27001, with ISO/IEC 27017 (information security controls for cloud services) and ISO/IEC 27018 (protection of personally identifiable information (PII) in public clouds) assessed as extensions within the same certified scope for the Flowvenue SaaS platform. For how we design and operate service management—change control, incident handling, service ownership, and continual improvement—we adopt ITIL 4 as our reference framework; see Service management & ITIL 4. ISO/IEC 27001 is the certified management-system standard for information security on the SaaS platform. This page provides a high-level overview of the certified ISMS; certificate extracts, scope statements, and registration details are available to authorised parties on formal request — see Verification & Evidence.


Information Security Management System (ISMS)

What Is an ISMS?

An Information Security Management System (ISMS) is a systematic approach to managing sensitive information so that it remains secure. It includes people, processes, and technology.

Our ISMS Scope

Our ISMS covers the Flowvenue SaaS Platform and all systems, processes, and infrastructure necessary for its delivery, including:

Exclusions

Our ISMS does not directly cover:


Security Principles

CIA Triad

We adopt the CIA (Confidentiality, Integrity, Availability) model as the foundation of information security:

Confidentiality

Information is accessible only to authorized individuals:

Integrity

Information is accurate, complete, and unaltered:

Availability

Information is accessible when needed:


Risk-Based Approach

Our Methodology

Flowvenue adopts a risk-based approach to information security management:

  1. Risk Identification - Systematic identification of information security risks
  2. Risk Assessment - Evaluation of probability and impact, distinguishing inherent (intrinsic) risk from residual risk after controls and treatment, using qualitative scales (Low / Medium / High)
  3. Risk Treatment - Appropriate strategies (mitigate, accept, transfer, avoid)
  4. Risk Monitoring - Continuous monitoring and periodic review

Organisational risk appetite: acceptance thresholds and escalation rules for Low / Medium / High are defined and approved at ISMS level (documented in the controlled Information Security Policy and Risk Assessment Methodology; available to authorised parties on formal request — see Verification & Evidence).

Risk Management Process

Risks are:


Security Objectives

Data Protection

Service Availability

Access Management

Awareness and Training


Governance

Management Commitment

Flowvenue management is committed to:

Roles and Responsibilities

Information security responsibilities are clearly defined:

Continuous Improvement

We regularly review and improve our ISMS through:


Compliance and Standards

Regulations

Flowvenue is committed to compliance with:

Standards

Certifications Flowvenue holds: ISO 9001 (quality management), ISO/IEC 27001, ISO/IEC 27017, and ISO/IEC 27018 (see below). Continuity, backup, service operations, and related practices are not part of the ISMS certificate’s scope; they are described through internal procedures and the Service management & ITIL 4 page, with public links under Other guidance and in Verification & Evidence.

Certified standards

Continuity and service operations (outside the ISMS certificate)

Continuity, backup, incident handling, and day-to-day service management are governed by internal procedures and by the Service management & ITIL 4 overview. Public evidence includes Backup and restore procedure, Cloud / SaaS service incident procedure, and materials reachable from Verification & Evidence. This material is published for transparency and procurement due diligence; it does not extend accredited certification beyond ISO/IEC 27001 / 27017 / 27018.

Other guidance

Contractual Obligations

We support and manage:


Security Controls

High-Level Categories

Our security controls cover:

Statement of Applicability

A Statement of Applicability (SoA) documents which ISO/IEC 27001 Annex A controls are applicable to our ISMS and how they are implemented.

Note: The detailed SoA is an internal document and is available upon formal request for authorized parties (auditors, certification bodies, enterprise clients under NDA).


Incident Management

Incident Response

We have defined procedures for:

The public Security incident response procedure describes the operational cycle (including triage, evidence correlation, stakeholder communications, incident metrics at ISMS level, annual review and planned testing such as tabletop exercises, and training when the plan is materially updated). It is aligned with ISO/IEC 27035 principles. Service-impacting operational incidents are handled under the Cloud / SaaS service incident procedure; personal data breaches under the Data breach procedure and the DPA. Requirements specific to public administration clients, voluntary CSIRT Italy reporting, or a formally named CERT / external IR provider are addressed in contractual security annexes where applicable (see the table in the incident response procedure).

Reporting

Security incidents are:


Third-Party Security

Vendor Management

We assess and manage security risks from third-party vendors:

Cloud Providers

Production workloads for the Flowvenue service run on Amazon Web Services (AWS) in the Milan (eu-south-1) region, European Union, for compute, managed databases, object storage, and related services, under the AWS shared responsibility model. Non-production environments may use additional or alternate hosts for engineering purposes; their scope is documented internally and does not change the production commitment stated here.

Identity provider (Auth0)

End-user and administrator authentication for the product is provided through Auth0 (Okta) with the tenant configured in the European Union data region, in line with Auth0’s regional deployment options for EU customers.

AI / LLM services — platform-managed, model selection, BYOK, and MCP

Flowvenue uses large language models (LLMs) for conversational AI, process design, translation assist, and related product features. Depending on the Customer’s configuration and plan, inference may run through Flowvenue-managed credentials, the Customer’s own credentials (Bring Your Own Key — BYOK), or an external LLM client connected via Flowvenue MCP Server. Contractual detail on BeeCoin, model tiers, and BYOK is in the Terms of Service (Section 10).

Default provider and model selection

Unless the Customer configures otherwise, Flowvenue uses OpenAI with GPT-5.6 Luna (gpt-5.6-luna) as the default model for the conversational assistant and process design. Where supported by the Customer’s plan and organization settings, the Customer may select alternative models among those explicitly supported and allowlisted by Flowvenue (for example OpenAI or Anthropic models classified as economy, balanced, or premium tiers). Flowvenue may update default providers or models with reasonable notice of material changes.

Platform-managed LLM (Flowvenue credentials)

When the Customer uses LLM inference with Flowvenue-managed API credentials (BeeCoin-metered usage), Flowvenue engages approved LLM subprocessors, typically including:

Provider Typical use Public compliance entry points
OpenAI Default conversational and design workloads Trust portal, Data controls
Anthropic Alternative models where enabled Anthropic Trust Center, Commercial terms / DPA

For OpenAI Enterprise arrangements in force:

For Anthropic, contractual and security materials (including commercial DPA and data-handling commitments) are available from Anthropic’s Trust Center and published legal documentation. Exact retention, training, and residency scope follow the agreement in force between Flowvenue and each provider.

Note: Platform-managed LLM subprocessors are listed in the DPA Annex / sub-processor register and are subject to Flowvenue’s vendor due diligence (Vendor due diligence procedure).

Bring Your Own Key (BYOK) and external or private LLM endpoints

Customers may configure their own API credentials for LLM inference (OpenAI, Anthropic, or a compatible endpoint, including dedicated cloud deployments or private/on‑premise LLM infrastructure managed by the Customer or its vendor). In this mode:

Flowvenue MCP Server and external LLM clients

Flowvenue exposes an inbound MCP Server so that external LLM clients (for example Claude, ChatGPT, Gemini, or Copilot with MCP support) can connect to the Customer’s organization to configure processes, read/write data within granted scopes, and operate workflows without Flowvenue performing LLM inference for that interaction path.

Customers enabling MCP for external clients remain responsible for securing their LLM client, OAuth consent, and any data processed by their LLM vendor.

Shared responsibility summary

Mode Who performs LLM inference Typical Flowvenue role Customer responsibility
Platform-managed LLM Flowvenue via approved subprocessors Processor / orchestrator; sub-processor management for listed LLM vendors Lawful data, process design, human oversight
BYOK (web chat / native assistant) Customer’s LLM provider or private endpoint Orchestrator; encrypts and uses Customer-supplied keys only for configured calls Provider compliance, key rotation, endpoint security
External LLM via MCP Server Customer’s LLM client (cloud or private) MCP tool host; authorization, scopes, audit LLM client security, OAuth approval, vendor due diligence on chosen LLM

Further evidence (sub-processor lists, DPA excerpts, provider attestations) may be requested under NDA or through Verification & Evidence.


Audit and Certification

Internal Audits

We conduct regular internal audits to:

External Audits

We engage with:

Certification Status

Current status: Flowvenue holds accredited certification for ISO/IEC 27001 (ISMS), with ISO/IEC 27017 and ISO/IEC 27018 included as certified extensions for the Flowvenue SaaS platform, within the scope defined on the certificate. Certificate identification, scope wording, and validity are shared with auditors, procurement, and clients under Verification & Evidence or contractually as agreed.

Note: Detailed audit reports, risk registers, and control implementations remain internal documents available upon formal request for authorized parties.


Structured Security Requirements

A structured overview of security measures and supplier requirements (by topic), with an index for quick lookup, is available in Security measures and supplier requirements. That document covers organisational, architectural, access control, data protection, logging, malware and network security, security assessment, data protection regulation, certifications, accessibility and performance in a single place.


Transparency and Disclosure

What We Disclose Publicly

This page provides:

What We Do Not Disclose Publicly

For security reasons, we do not publicly disclose:

Why? Public disclosure of these details could:

Access to Detailed Documentation

Detailed ISMS documentation, including:

...is available upon formal request for:

Note: Flowvenue reserves the right to evaluate and limit access to documentation based on the legitimacy, proportionality, and applicability of the request.


Contact

For information security, ISMS, and company CSIRT / IRT coordination: Marcello Riccimricci@flowvenue.com.

For opening incidents or general security enquiries via the operational intake channel: info@flowvenue.com and WhatsApp +39 350 998 6359.

PEC: flowvenue@pecimprese.it


Note: This page provides a high-level overview of our information security framework. Detailed ISMS documentation is available upon formal request for authorized parties (auditors, certification bodies, enterprise clients under NDA).

Summary: Flowvenue’s ISMS is certified to ISO/IEC 27001, with ISO/IEC 27017 and ISO/IEC 27018 as certified extensions for the Flowvenue SaaS platform within the scope stated on the certificate. Service-management and continuity practices are documented separately via ITIL 4 alignment and internal procedures, without implying additional accredited certifications beyond that ISMS scope.