Verified product boundaries
Business records are scoped by workspace and project on the server. Product roles, restricted folders, scoped review and delivery links, expiry and revocation controls, private object storage, credit ledgers, and operational audit records are part of the implemented service boundary.
Public-link access and file delivery use server-side checks. Payment webhook processing is signature-verified and designed for idempotent reconciliation. Provider secrets and raw payloads are not intended for browser-visible responses.
Customer responsibility
Customers remain responsible for classifying content, choosing recipients, configuring access, reviewing AI output, satisfying client contracts, obtaining consent, and determining whether AssetsFlow is appropriate for a regulated workflow.
Current limitations
AssetsFlow does not currently claim SOC 2 or ISO 27001 certification, HIPAA compliance, PCI DSS service-provider certification, dedicated data residency, enterprise SSO/SCIM, a public bug bounty, or zero-data-retention processing. Payment card data is handled by Stripe, but that does not make every AssetsFlow workflow PCI certified.
Production guarantees depend on the deployed environment and provider configuration. Contact [email protected] for a current technical or procurement review rather than relying on this page as a warranty.