Information Security (ISO/IEC 27001, 27017, 27018)
Certified ISMS under ISO/IEC 27001 with ISO/IEC 27017 and ISO/IEC 27018 extensions; continuity and service operations described separately.
Last updated: June 2026 Version: 2026.06
Our Commitment to Information Security
Flowvenue operates an Information Security Management System (ISMS) that has been certified under ISO/IEC 27001, with ISO/IEC 27017 (information security controls for cloud services) and ISO/IEC 27018 (protection of personally identifiable information (PII) in public clouds) assessed as extensions within the same certified scope for the Flowvenue SaaS platform. For how we design and operate service management—change control, incident handling, service ownership, and continual improvement—we adopt ITIL 4 as our reference framework; see Service management & ITIL 4. ISO/IEC 27001 is the certified management-system standard for information security on the SaaS platform. This page provides a high-level overview of the certified ISMS; certificate extracts, scope statements, and registration details are available to authorised parties on formal request — see Verification & Evidence.
Information Security Management System (ISMS)
What Is an ISMS?
An Information Security Management System (ISMS) is a systematic approach to managing sensitive information so that it remains secure. It includes people, processes, and technology.
Our ISMS Scope
Our ISMS covers the Flowvenue SaaS Platform and all systems, processes, and infrastructure necessary for its delivery, including:
- Web applications and user interfaces
- Backend APIs and services
- Databases and data storage
- Cloud infrastructure and hosting
- Development and operations processes
- Support and customer service
Exclusions
Our ISMS does not directly cover:
- Physical infrastructure of cloud providers (managed through shared responsibility model)
- Third-party services (managed through contractual agreements and risk assessment)
- Client on-premise systems (client responsibility)
Security Principles
CIA Triad
We adopt the CIA (Confidentiality, Integrity, Availability) model as the foundation of information security:
Confidentiality
Information is accessible only to authorized individuals:
- Protection of sensitive and personal data
- Access control based on least privilege principle
- Encryption of data in transit and at rest: application-level encryption (AES-256-GCM) for sensitive secrets and tokens; infrastructure-level encryption for databases and storage on AWS; encryption at rest for file attachments stored on AWS
- Information classification according to sensitivity levels
Integrity
Information is accurate, complete, and unaltered:
- Data integrity controls
- Change traceability where applicable (audit trail)
- Input validation
- Protection against tampering and corruption
Availability
Information is accessible when needed:
- Redundancy and backups
- Business continuity planning
- Monitoring and preventive maintenance
- Capacity management
Risk-Based Approach
Our Methodology
Flowvenue adopts a risk-based approach to information security management:
- Risk Identification - Systematic identification of information security risks
- Risk Assessment - Evaluation of probability and impact, distinguishing inherent (intrinsic) risk from residual risk after controls and treatment, using qualitative scales (Low / Medium / High)
- Risk Treatment - Appropriate strategies (mitigate, accept, transfer, avoid)
- Risk Monitoring - Continuous monitoring and periodic review
Organisational risk appetite: acceptance thresholds and escalation rules for Low / Medium / High are defined and approved at ISMS level (documented in the controlled Information Security Policy and Risk Assessment Methodology; available to authorised parties on formal request — see Verification & Evidence).
Risk Management Process
Risks are:
- Documented in a risk register
- Assessed using a defined methodology (including threat and vulnerability inputs, CIA impact dimensions, and outcomes of VA/PT cycles — see Security assessment procedure and Security measures)
- Treated according to a risk treatment plan
- Reviewed regularly and updated as needed
Security Objectives
Data Protection
- Prevention, detection, and timely management of unauthorized access
- Encryption in transit and at rest: we use AWS as our primary infrastructure. Sensitive data (OAuth tokens, MFA secrets, channel credentials) are encrypted at application level (AES-256-GCM) before storage; databases and file storage (including attachments) benefit from AWS encryption at rest
- Regular backups and periodic restore verification
- GDPR and privacy regulation compliance
Service Availability
- Defined and monitored availability and business continuity objectives
- Regular backup and recovery plans
- Objectives may vary by environment and contractual agreements (SLA) and are defined in enterprise client contracts
Access Management
- Multi-factor authentication for privileged accounts
- Periodic access reviews
- Timely access revocation processes for departing employees
Awareness and Training
- Periodic mandatory security training for all employees
- Periodic security awareness activities
- Regular communication of best practices
Governance
Management Commitment
Flowvenue management is committed to:
- Providing resources necessary to implement and maintain the ISMS
- Supporting a security culture throughout the organization
- Ensuring compliance with legal, regulatory, and contractual requirements
- Periodically reviewing ISMS effectiveness
- Communicating the importance of security to all stakeholders
Roles and Responsibilities
Information security responsibilities are clearly defined:
- Management - Overall accountability and resource allocation
- Information Security Manager - ISMS implementation and coordination
- All Employees - Compliance with security policies and procedures
Continuous Improvement
We regularly review and improve our ISMS through:
- Internal audits
- Management reviews
- Risk assessments
- Incident analysis
- Stakeholder feedback
Compliance and Standards
Regulations
Flowvenue is committed to compliance with:
- GDPR (General Data Protection Regulation)
- ePrivacy Directive
- National privacy regulations
Standards
Certifications Flowvenue holds: ISO 9001 (quality management), ISO/IEC 27001, ISO/IEC 27017, and ISO/IEC 27018 (see below). Continuity, backup, service operations, and related practices are not part of the ISMS certificate’s scope; they are described through internal procedures and the Service management & ITIL 4 page, with public links under Other guidance and in Verification & Evidence.
Certified standards
- ISO 9001 — Quality management systems (certified). Flowvenue maintains a certified QMS for the development and delivery of its technology platform. ISO 9001 is distinct from the ISMS certificate; certificate extracts and formal evidence are available under Verification & Evidence.
- ISO/IEC 27001 — Information security management systems (certified). The ISMS is certified for the Flowvenue SaaS platform within the scope defined by the certificate (statement of applicability and SoA evidence on formal request).
- ISO/IEC 27017 — Information security controls for cloud services (certified as an extension to the ISO/IEC 27001 certification, covering how cloud-service security controls are applied for our SaaS delivery model).
- ISO/IEC 27018 — Protection of PII in public clouds (certified as an extension to the ISO/IEC 27001 certification, covering processing of personal data in our public-cloud environment).
Continuity and service operations (outside the ISMS certificate)
Continuity, backup, incident handling, and day-to-day service management are governed by internal procedures and by the Service management & ITIL 4 overview. Public evidence includes Backup and restore procedure, Cloud / SaaS service incident procedure, and materials reachable from Verification & Evidence. This material is published for transparency and procurement due diligence; it does not extend accredited certification beyond ISO/IEC 27001 / 27017 / 27018.
Other guidance
- Best practices — OWASP, NIST, and industry standards. Flowvenue performs combined VA and penetration testing through a qualified external provider, typically in April, August, and December each year (with a written report after each cycle), while keeping a maximum four-month gap between cycles unless rescheduled with internal traceability. Ongoing internal practices include code review, dependency checks, and container image scanning. Client-facing outcome documents (sanitized / executive summary) are published for all customers under VA/PT evidence and
/compliance/reports/. See also Security measures — §1.9 and Security assessment procedure.
Contractual Obligations
We support and manage:
- Service Level Agreements (SLA) with clients (where applicable)
- Data Processing Agreements (DPA)
- Vendor agreements
Security Controls
High-Level Categories
Our security controls cover:
- Access Control - Authentication, authorization, and access management
- Cryptography - Encryption of data in transit and at rest (application-level AES-256-GCM for secrets; AWS encryption at rest for DB and attachments)
- Physical and Environmental Security - Managed through cloud provider controls
- Operations Security - Secure operations, change management, backup
- Environment separation - Development and test environments are separated from production both logically (ENV_BUILD configuration) and at infrastructure level; on AWS we use two separate clusters with network separation (see Security measures and supplier requirements)
- Logging and monitoring - First-party telemetry records user access and activity (sessions, page visits, product events) in the database; security-relevant events (e.g. blocked requests) are recorded in dedicated logs. Data can be extracted from the database for audit or for feeding the client’s SIEM, according to agreed modalities (see Security measures and supplier requirements).
- Communications Security - Secure network communications
- Malware protection - Anti-malware and related controls are provided at infrastructure level by AWS (shared responsibility model); see Security measures and supplier requirements
- System Acquisition and Development - Secure development lifecycle
- Supplier Relationships - Security requirements for suppliers
- Information Security Incident Management - Incident response procedures
- Business Continuity - Continuity planning and disaster recovery guided by internal procedures (Backup and restore procedure, Cloud / SaaS service incident procedure, Service management & ITIL 4)
- Compliance - Legal, regulatory, and contractual compliance
Statement of Applicability
A Statement of Applicability (SoA) documents which ISO/IEC 27001 Annex A controls are applicable to our ISMS and how they are implemented.
Note: The detailed SoA is an internal document and is available upon formal request for authorized parties (auditors, certification bodies, enterprise clients under NDA).
Incident Management
Incident Response
We have defined procedures for:
- Detection - Identifying security incidents
- Response - Containing and mitigating incidents
- Recovery - Restoring normal operations
- Lessons Learned - Improving based on incidents
The public Security incident response procedure describes the operational cycle (including triage, evidence correlation, stakeholder communications, incident metrics at ISMS level, annual review and planned testing such as tabletop exercises, and training when the plan is materially updated). It is aligned with ISO/IEC 27035 principles. Service-impacting operational incidents are handled under the Cloud / SaaS service incident procedure; personal data breaches under the Data breach procedure and the DPA. Requirements specific to public administration clients, voluntary CSIRT Italy reporting, or a formally named CERT / external IR provider are addressed in contractual security annexes where applicable (see the table in the incident response procedure).
Reporting
Security incidents are:
- Documented and tracked
- Analyzed for root causes
- Used to improve security controls
- Reported to relevant stakeholders when required
Third-Party Security
Vendor Management
We assess and manage security risks from third-party vendors:
- Due Diligence - Security assessment before engagement
- Contracts - Security requirements in vendor agreements
- Monitoring - Ongoing assessment of vendor security
- Shared Responsibility - Clear understanding of security responsibilities
Cloud Providers
Production workloads for the Flowvenue service run on Amazon Web Services (AWS) in the Milan (eu-south-1) region, European Union, for compute, managed databases, object storage, and related services, under the AWS shared responsibility model. Non-production environments may use additional or alternate hosts for engineering purposes; their scope is documented internally and does not change the production commitment stated here.
Identity provider (Auth0)
End-user and administrator authentication for the product is provided through Auth0 (Okta) with the tenant configured in the European Union data region, in line with Auth0’s regional deployment options for EU customers.
AI / LLM services — platform-managed, model selection, BYOK, and MCP
Flowvenue uses large language models (LLMs) for conversational AI, process design, translation assist, and related product features. Depending on the Customer’s configuration and plan, inference may run through Flowvenue-managed credentials, the Customer’s own credentials (Bring Your Own Key — BYOK), or an external LLM client connected via Flowvenue MCP Server. Contractual detail on BeeCoin, model tiers, and BYOK is in the Terms of Service (Section 10).
Default provider and model selection
Unless the Customer configures otherwise, Flowvenue uses OpenAI with GPT-5.6 Luna (gpt-5.6-luna) as the default model for the conversational assistant and process design. Where supported by the Customer’s plan and organization settings, the Customer may select alternative models among those explicitly supported and allowlisted by Flowvenue (for example OpenAI or Anthropic models classified as economy, balanced, or premium tiers). Flowvenue may update default providers or models with reasonable notice of material changes.
Platform-managed LLM (Flowvenue credentials)
When the Customer uses LLM inference with Flowvenue-managed API credentials (BeeCoin-metered usage), Flowvenue engages approved LLM subprocessors, typically including:
| Provider | Typical use | Public compliance entry points |
|---|---|---|
| OpenAI | Default conversational and design workloads | Trust portal, Data controls |
| Anthropic | Alternative models where enabled | Anthropic Trust Center, Commercial terms / DPA |
For OpenAI Enterprise arrangements in force:
- Zero Data Retention (ZDR): eligible API use follows OpenAI’s Zero Data Retention policy so that customer content is not retained beyond what is technically required to fulfil each request, subject to OpenAI’s published ZDR rules and Modified Abuse Monitoring where applicable. Reference: Zero Data Retention.
- Use for model training: under OpenAI’s published policies for API and Enterprise customers, customer content is not used to train or improve OpenAI models unless the Customer explicitly opts in.
- Europe — processing and residency: processing is aligned with OpenAI options for data processing in the EU / European residency for the configured Enterprise deployment.
For Anthropic, contractual and security materials (including commercial DPA and data-handling commitments) are available from Anthropic’s Trust Center and published legal documentation. Exact retention, training, and residency scope follow the agreement in force between Flowvenue and each provider.
Note: Platform-managed LLM subprocessors are listed in the DPA Annex / sub-processor register and are subject to Flowvenue’s vendor due diligence (Vendor due diligence procedure).
Bring Your Own Key (BYOK) and external or private LLM endpoints
Customers may configure their own API credentials for LLM inference (OpenAI, Anthropic, or a compatible endpoint, including dedicated cloud deployments or private/on‑premise LLM infrastructure managed by the Customer or its vendor). In this mode:
- Inference billing and subprocessors: LLM inference is billed by the Customer’s provider; Flowvenue does not charge BeeCoin for LLM inference performed with Customer credentials. The LLM provider chosen by the Customer (including private or regional deployments) is outside Flowvenue’s sub-processor list for that inference path; the Customer remains responsible for that provider’s compliance, residency, and contractual terms.
- Protection of Customer keys: API keys supplied for BYOK are stored encrypted at application level (AES-256-GCM) before persistence; they are used only to perform inference on the Customer’s behalf within the configured provider/model pair.
- Platform services: Flowvenue continues to provide orchestration, process runtime, integrations, MCP tooling, and other platform features according to the subscribed plan; non-LLM BeeCoin consumption may still apply where configured.
Flowvenue MCP Server and external LLM clients
Flowvenue exposes an inbound MCP Server so that external LLM clients (for example Claude, ChatGPT, Gemini, or Copilot with MCP support) can connect to the Customer’s organization to configure processes, read/write data within granted scopes, and operate workflows without Flowvenue performing LLM inference for that interaction path.
- Authorization: connections use OAuth 2.0 with PKCE (and, where configured, legacy inbound credentials in non-production environments only). Each connection is bound to organization context, integration user, and capability scopes defined in
mcp_config(read/write/design limits, rate limits, tool allowlists). - Data flows: business data and prompts needed to execute MCP tools transit between the Customer’s LLM environment (cloud or private) and Flowvenue APIs according to the scopes enabled by the Customer administrator. LLM inference in this model occurs on the Customer’s chosen LLM provider or private stack, not on Flowvenue-managed LLM credentials.
- Controls: MCP access is subject to RBAC, scope enforcement, rate limiting, audit logging of tool calls, and deterministic runtime guards (for example blocking operational placeholder values in process design). See also Security measures — §1.5.
Customers enabling MCP for external clients remain responsible for securing their LLM client, OAuth consent, and any data processed by their LLM vendor.
Shared responsibility summary
| Mode | Who performs LLM inference | Typical Flowvenue role | Customer responsibility |
|---|---|---|---|
| Platform-managed LLM | Flowvenue via approved subprocessors | Processor / orchestrator; sub-processor management for listed LLM vendors | Lawful data, process design, human oversight |
| BYOK (web chat / native assistant) | Customer’s LLM provider or private endpoint | Orchestrator; encrypts and uses Customer-supplied keys only for configured calls | Provider compliance, key rotation, endpoint security |
| External LLM via MCP Server | Customer’s LLM client (cloud or private) | MCP tool host; authorization, scopes, audit | LLM client security, OAuth approval, vendor due diligence on chosen LLM |
Further evidence (sub-processor lists, DPA excerpts, provider attestations) may be requested under NDA or through Verification & Evidence.
Audit and Certification
Internal Audits
We conduct regular internal audits to:
- Verify ISMS effectiveness
- Identify areas for improvement
- Ensure compliance with policies and procedures
- Support certification body surveillance and recertification cycles
External Audits
We engage with:
- Certification Bodies — Surveillance and recertification of ISO/IEC 27001 together with ISO/IEC 27017 and ISO/IEC 27018 within the certified scope for the Flowvenue SaaS platform
- Regulatory Authorities - For compliance verification
- Enterprise Clients - Deeper due diligence on ISMS artifacts beyond public VA/PT outcome documents (cycle PDFs are the same for all clients; further annexes may be shared under NDA where agreed)
Certification Status
Current status: Flowvenue holds accredited certification for ISO/IEC 27001 (ISMS), with ISO/IEC 27017 and ISO/IEC 27018 included as certified extensions for the Flowvenue SaaS platform, within the scope defined on the certificate. Certificate identification, scope wording, and validity are shared with auditors, procurement, and clients under Verification & Evidence or contractually as agreed.
Note: Detailed audit reports, risk registers, and control implementations remain internal documents available upon formal request for authorized parties.
Structured Security Requirements
A structured overview of security measures and supplier requirements (by topic), with an index for quick lookup, is available in Security measures and supplier requirements. That document covers organisational, architectural, access control, data protection, logging, malware and network security, security assessment, data protection regulation, certifications, accessibility and performance in a single place.
Transparency and Disclosure
What We Disclose Publicly
This page provides:
- High-level overview of our ISMS
- Security principles and objectives
- Governance approach
- Compliance commitments
What We Do Not Disclose Publicly
For security reasons, we do not publicly disclose:
- Detailed risk assessments
- Specific security controls and implementations
- Asset inventories
- Incident response procedures
- Internal audit findings
- Technical architecture details
Why? Public disclosure of these details could:
- Reveal system architecture and attack surfaces
- Expose specific vulnerabilities
- Compromise security measures
- Violate confidentiality obligations
Access to Detailed Documentation
Detailed ISMS documentation, including:
- Risk Register
- Statement of Applicability (SoA)
- Internal audit reports
- Incident response plans
- Asset inventories
...is available upon formal request for:
- ISO/IEC 27001 / 27017 / 27018 certification audits and surveillance evidence
- Regulatory compliance audits
- Enterprise client due diligence (under NDA)
- Legal proceedings
Note: Flowvenue reserves the right to evaluate and limit access to documentation based on the legitimacy, proportionality, and applicability of the request.
Contact
For information security, ISMS, and company CSIRT / IRT coordination: Marcello Ricci — mricci@flowvenue.com.
For opening incidents or general security enquiries via the operational intake channel: info@flowvenue.com and WhatsApp +39 350 998 6359.
Note: This page provides a high-level overview of our information security framework. Detailed ISMS documentation is available upon formal request for authorized parties (auditors, certification bodies, enterprise clients under NDA).
Summary: Flowvenue’s ISMS is certified to ISO/IEC 27001, with ISO/IEC 27017 and ISO/IEC 27018 as certified extensions for the Flowvenue SaaS platform within the scope stated on the certificate. Service-management and continuity practices are documented separately via ITIL 4 alignment and internal procedures, without implying additional accredited certifications beyond that ISMS scope.