FlowLeap
  • How It Works▾
  • What We Handle▾
  • About
  • Security
  • Blog
Security & Compliance

A Controlled Software Layer, Not a Consumer Chatbot

Your clients trust you with their financial data. FlowLeap is built as a controlled processing and workflow layer - AWS-hosted, encrypted, access-scoped, with model inference routed through Amazon Bedrock and human approval for high-impact actions. Here is exactly how it works.

Standards & Posture

How We Are Assessed

GDPR
EU / UK - Data Processing Agreement
European Clients
POPIA
SA - Protection of Personal Information Act
SA Clients
Encryption
In transit and at rest
Active
Amazon Bedrock
Controlled model inference
Active
Data Protection

How We Protect Your Data

The controls expected from a professional external software provider - applied from the moment data enters a workflow to the moment a connection is revoked.

Hosting

Production client-data workflows run in the AWS Europe (Ireland) region, eu-west-1. Client data remains inside the FlowLeap AWS-hosted environment and the approved inference route - it is not copied into public tools.

Encryption

Client data is encrypted in transit and at rest, using AWS-managed, KMS-backed encryption. Older, insecure transport protocols are not used.

Secrets & Credentials

OAuth refresh tokens, API keys, credentials, and connection secrets are held in approved production secret stores and protected by AWS KMS-backed controls - separated from the data they unlock.

Scoped Source Access

Access to mailboxes, document stores, PDFs, ledgers, and payroll sources is scoped to the approved clients, books, folders, and workflow purposes. Access is never treated as permission to process everything in a connected system.

Read / Write Separation

The default starting position is read-only. Sending email, changing ledgers, releasing payroll, or submitting statutory records stays disabled unless a named write capability and its approval path are separately agreed.

Client Separation

Data is separated by firm, client, book, source connection, user, and workflow scope - enforced by database-level row access controls (or a documented datastore isolation control) plus application-level checks.

Controlled Logging

Operational logs are built around metadata and redacted by default. Any content-bearing logs, prompts, outputs, or support records are treated as client data. Model invocation logging is disabled unless agreed for a defined purpose.

Revocation & Offboarding

Revocation disables the relevant source connection, stops new processing, invalidates tokens where supported, and records completion. Retention and offboarding follow the approach agreed in the engagement.

Model-Assisted Processing

Why This Is Not Consumer Chatbot Use

When FlowLeap uses AI, it means model inference as one controlled step inside a workflow - not a public chatbot with open-ended access to your data.

Routed Through Amazon Bedrock

Standard client-data workflows run model inference through Amazon Bedrock, AWS's managed service for foundation models behind an enterprise service boundary. Any Anthropic models used are invoked as Bedrock-hosted models.

No Consumer Tools

Client data is not sent to consumer Claude.ai or ChatGPT, nor to any direct public model API. Standard workflows also do not use Cross-Region or global Bedrock inference profiles.

Inference, Not Training

Your data is used to run tasks, not to train models. Client data is not used to train base models through the approved Bedrock route, and is not used for cross-client model training, fine-tuning, or customisation.

Task-Scoped Context

The workflow sends only the task-specific context a step needs. The model does not receive independent or unrestricted access to your mailboxes, document stores, ledgers, or payroll systems.

Reviewable Outputs

Model output is a reviewable work item - an extraction, classification, summary, or draft linked to its source references - that your team can accept, correct, or reject. It is never treated as a final answer on its own.

Approval-Gated Actions

External, irreversible, ledger-changing, payroll-impacting, or client-facing actions pass through a human approval gate by default before anything is executed.

Data Privacy & Compliance

Your Clients' Data Belongs to Your Clients

FlowLeap acts as a data processor - an operator - on behalf of your firm. Your firm retains data ownership and control at all times. We process your clients' data only to deliver the services you've contracted us to provide - never for advertising, model training, or sale to third parties.

South African firms - We generally act as an operator under POPIA, processing personal information on your firm's instructions. The production environment is hosted in AWS Ireland (eu-west-1), so for South African personal information this is a cross-border arrangement: the engagement records the operator role, the POPIA section 72 transfer basis, approved sub-operators (such as AWS), security obligations, retention, and incident-notification position.

European firms - Our Data Processing Agreement (DPA) covers the required GDPR obligations for EU-based firms and is compatible with UK GDPR for firms in the United Kingdom.

Each firm remains responsible for confirming the appropriate lawful basis and client notices for the underlying client data. Subject access, deletion, and portability requests are supported under both POPIA and GDPR.

✓ Data Ownership

You own your data. Always. We have no right to use your clients' financial data beyond service delivery.

✓ No Training on Your Data

Your firm's data is never used to train AI models that serve other customers. Your workflows remain yours.

✓ Deletion & Offboarding

On termination, your data is removed in line with the agreed retention and offboarding process, with completion recorded.

✓ Sub-Processor Transparency

Approved sub-processors (such as AWS) are recorded in the engagement, with their role and service layer defined.

Responsible AI

AI That Knows What It Doesn't Know

Our AI colleagues are built with explicit boundaries - and designed to escalate rather than guess.

🚦

Human-in-the-Loop Review

AI colleagues never send client communications without human review and approval. Your team controls what goes out - always.

⚠️

Escalation by Default

When an AI colleague encounters ambiguity, complexity, or an exception it hasn't been trained on, it flags the item for human review - it does not attempt to resolve it alone.

📐

Bounded Scope

AI colleagues operate within strictly defined workflows. They do not have access to systems, data, or actions outside their configured scope. Permissions are explicit and auditable.

🔍

Explainable Actions

Every action is recorded with its workflow context and source references. Your team can review exactly what was done, why, and when - at any point in time.

Common Questions

Security FAQ

Who can access our firm's data?
Access to your firm's data is scoped to the approved clients, books, mailboxes, folders, and workflow purposes - plus a very limited set of FlowLeap personnel who require access for support and maintenance, subject to confidentiality obligations. All access is governed by client scope and recorded.
Is our client data used to train AI models?
No. Client data is not used to train base models through the approved Amazon Bedrock route, and is not used for cross-client model training, fine-tuning, or customisation. Model inference is used to run tasks at runtime - it is not model training. Any customisation using client data would require a separate documented approval process.
Where is our data processed and stored?
Production client-data workflows run in the AWS Europe (Ireland) region, eu-west-1, with client data encrypted in transit and at rest. For South African firms this is a cross-border processing arrangement under POPIA - the engagement records the section 72 transfer basis and the approved sub-operators. Client data stays inside the FlowLeap AWS environment and the approved Bedrock inference route.
Do you send our data to ChatGPT or Claude.ai?
No. Standard client-data workflows route model inference through Amazon Bedrock. Client data is not sent to consumer Claude.ai, ChatGPT, or any direct public model API, and standard workflows do not use Cross-Region or global Bedrock inference profiles. Per AWS's Bedrock documentation, inputs and outputs are not shared with model providers and are not used to train base models.
What happens to our data if we cancel?
On offboarding we disable the relevant source connections, stop new processing, invalidate tokens where supported, and remove data in line with the agreed retention and offboarding process, with completion recorded. You can request a confirmation, and export options can be agreed before removal.
How do you handle a data breach?
In the event of a confirmed security incident, we notify affected firms promptly - in line with GDPR Article 33 for European clients, and the POPIA-mandated timeframe for South African clients. Notification covers the nature of the incident, data affected, likely consequences, and remediation steps taken.
Can we get documentation for IT review?
Yes. We provide a Data Security and Model-Assisted Processing overview for client leadership, IT, and data-protection review, along with our DPA / operator agreement and the relevant AWS Bedrock references. Contact us to request the full pack under NDA where required for procurement.

You want to implement AI in your firm, but concerned about IT security?

We're happy to discuss specific requirements, provide the IT-review overview and operator agreement, or work through your firm's procurement process.

FlowLeap

Finance work, in motion. AI colleagues execute the work; your team reviews and signs off. Built for accounting firms.

Product

  • What We Handle
  • How It Works
  • Security

Company

  • About
  • Blog

Legal

  • Impressum
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
© 2026 FlowLeap