Security
Built on real architectural decisions, not marketing claims
Every principle below reflects an actual decision enforced in the Nexflow codebase — not an aspirational statement.
Multi-tenant isolation, enforced at the database
Every tenant-sensitive table enforces row-level security with explicit policies. Client-side filtering alone is never treated as sufficient access control — authorization is always re-derived server-side and at the database layer.
Platform access is structurally separate from client access
Internal platform administration is a structurally distinct role hierarchy from an organization's own membership roles — an ordinary client-side user can never self-grant platform-level access, and platform staff cannot touch a client organization's membership roster.
Secure, server-verified authentication
Session identity is re-validated against the authentication server on every authority decision, rather than trusting a locally cached session cookie alone.
Server-side authorization, not client-side trust
Every privileged action re-derives the caller's real permissions from the database. A client request is never trusted to assert its own authorization level.
Least privilege by default
Privileged database credentials are scoped narrowly to the specific server-side code that needs them, with explicit grants and revokes rather than relying on broad defaults.
Schema changes are migration-only
Database schema changes happen exclusively through version-controlled migrations — never ad hoc dashboard edits — so the system stays reproducible and auditable.
Append-only activity logging
Sensitive administrative and business actions are recorded to an append-only event log that ordinary application access cannot modify or delete.
Separate development and production environments
Development and production run on entirely separate infrastructure. Production changes require explicit review before promotion — development is never treated as a substitute for production testing.
Nexflow does not currently hold SOC 2, ISO 27001, HIPAA, or PCI certification. If compliance certification is a requirement for your business, please get in touch and we'll discuss your specific requirements directly.