Security overview
How mdflows protects your records
In plain language, with nothing held back for a sales call. Everything below applies to every plan, from Solo to Enterprise.
Isolation by design
Each organization gets its own database — a separate D1 database in mdflows Cloud, a separate SQLite file on-premises — and its files live under a prefix only that organization’s code path can address. The application receives a handle to one organization’s data at a time, so a query that reaches across organizations cannot be written, let alone run.
A record you can verify
Every change — a form published, a submission edited, an approval, a signature, a sign-in setting — is written in the same transaction as an audit entry. Each entry carries the cryptographic hash of the one before it, so altering or removing any past entry breaks the chain in a way the verification tool detects. The platform’s own operations (organizations created, plans changed) have a separate chain of their own.
Records are soft-deleted: a deletion is itself an audited event, and permanent removal happens only through retention rules, legal-hold-aware purges, or an organization’s requested deletion.
Signatures with evidence
Each signature stores the signer’s identity, the time, their network address and browser, the intent statement they agreed to, and the SHA-256 fingerprint of the exact documents and answers they signed — inside the audit chain. Outside signers receive single-use, expiring links; only a hash of each link is stored. A signed copy is always derived from the original, never an altered original, and its Certificate of Completion prints the fingerprints so anyone can check them.
Encryption and secrets
- Every connection is encrypted in transit (TLS); data at rest is encrypted by the storage platform.
- Credentials you give mdflows — mail and single-sign-on settings, database and SharePoint connections, AI provider keys, webhook signing secrets, two-factor seeds — are additionally sealed with AES-256-GCM, and the sealing key can be rotated without downtime.
- Passwords are stored only as salted, iterated PBKDF2-SHA256 hashes. Session, reset, invitation and API-key tokens are stored only as hashes.
Sign-in and access
- Two-factor authentication (authenticator apps, with recovery codes) on every plan, with an organization-wide requirement switch.
- Microsoft Entra ID and Google single sign-on with group-to-role mapping on Team and Enterprise.
- Accounts lock after repeated failed sign-ins; sign-in, reset and public form endpoints are rate-limited.
- Roles plus per-cabinet and per-form permissions, enforced by the server on every request — hiding a button is never the protection.
- Every active session can be seen and revoked; API keys are scoped, expiring and revocable.
Hardened pages
Public form, signing and website pages send a strict Content Security Policy with a fresh nonce on every request, so only mdflows’ own inline code can run. Form pages load no third-party scripts at all. Pages refuse to be framed by other sites (except form pages, which you may embed on purpose), state-changing requests must come from the same origin, and oversized requests are refused before they are read.
Backups and recovery
- mdflows Cloud
- Every organization database has point-in-time recovery to any minute of the last 30 days (Cloudflare D1 Time Travel). Files are stored on Cloudflare R2, designed for 99.999999999% annual durability.
- On-premises
- Scheduled backups of every database and file, plus a restore drill that restores into a scratch area, checks database integrity, re-verifies both audit chains and re-hashes every file.
AI, on your terms
AI features are off until an administrator enables them and records consent. The assistant proposes changes as a reviewable diff; a person applies them, and it cannot delete anything. Document suggestions need their own separate consent. Usage is metered per month, and prompt text is never written to the audit log. Bring your own provider key, use our hosted model, or — on-premises — a local model so nothing leaves your building.
Accessibility
Automated WCAG 2.1 AA checks run against the public form pages, the reviewer queue and the admin pages on every build. A new violation fails the build, the same way a failing test does.
Privacy by default
No advertising or analytics trackers run on this site or on your forms. Pending signup details are discarded once an organization is created. Data-subject requests (access and erasure) are supported by built-in tooling with an audit trail. Read the privacy policy.
What we don’t have yet
Honesty is part of security, so: mdflows does not yet have a SOC 2 report, SAML or SCIM provisioning, or a published third-party penetration test. Upload virus scanning is available on-premises but not yet in mdflows Cloud. We will update this page when any of that changes.
Report a vulnerability
Email help@mdflows.com with the details. Please give us a reasonable chance to fix an issue before disclosing it; we will not pursue good-faith research that respects your privacy and ours.
Put your first form to work today.
30 days, every feature, no credit card. Your first form can be live this afternoon.