Your data is secure and protected.

    Never used to train AI, kept separate from every other customer, and covered by an independently audited security programme.

    Short answers, up front.

    Private.

    We never train AI on your data.

    Your data is used to deliver your engagement. Nothing else. Our AI providers are engaged under enterprise agreements that explicitly prohibit training on submitted data.

    Isolated.

    Your data is kept separate from every other customer.

    Not combined, mixed, or benchmarked against another client's data. Each engagement is kept separate end to end.

    Self-contained.

    No integration with your systems required.

    Our default engagement does not connect into your systems, so there is no API build and no work for your IT team. We work from data you send us through a secure transfer.

    Your data is secure and protected.

    SOC 2

    Type I attested. Type II audit in progress.

    Enterprise cloud services

    Hosted on Microsoft Azure, our sole subprocessor.

    Encrypted

    Encrypted in transit and at rest.

    Continuously monitored

    Ongoing vulnerability and system monitoring.

    Independently tested

    Penetration tested at least annually by an independent third party.

    Never trains AI

    We never use your data to train AI models.

    We have been through enterprise security review in financial services, health, government and education. Your IT, security and legal teams will have seen all of this before.

    Easy for your IT, data security and legal teams.

    Everything your reviewers need in one place: certifications, subprocessors, controls, and evidence. Send them the link and let them self-serve — or ask us for a full pack.

    How we keep your data safe

    You are focused on impact, not security certificates. So here it is simply: keeping your data safe is non-negotiable. Here is what we do, every day.

    • SOC 2 compliant, independently audited

      An independent auditor has verified our security controls. Type I is attested and the Type II audit is in progress.

    • Continuous monitoring

      Vulnerability and system monitoring run against our infrastructure and dependencies on an ongoing basis, alongside annual control self-assessments.

    • Independent penetration testing

      An independent third party tests our systems at least annually, and findings are tracked through to remediation.

    • Tight access control

      Access is role-based and granted at the minimum level necessary. Privileged access to databases, systems and networks is restricted, and access is revoked on termination.

    • Deleted when you leave

      We hold data under defined retention and disposal procedures, governed by a data classification policy. When you leave, your data is deleted.

    Common questions

    Your data and AI

    • No. Flowing Bee does not use client data to train AI models. Your data is used to deliver your engagement and nothing else.
    • Each client engagement is kept separate. Your data is not combined with another client's, and it is not used for syndicated benchmarking. What we can and cannot do with your data is set out in your contract with us. If you need a specific confidentiality or non-syndication commitment in writing, raise it at scoping.
    • Data you upload or share with us originates from you and remains yours. The outputs of a behavioural diagnosis, and the content we create from it, are Flowing Bee's intellectual property, licensed to you under your engagement. Your contract sets out the split in full.

    Where and how your data lives

    • On Microsoft Azure, our sole subprocessor. Your data is encrypted in transit and at rest. If your organisation has specific data residency requirements, raise them at engagement scoping and we will confirm what we can support.
    • Microsoft Azure is our only subprocessor. The current list is published in our trust centre at trust.flowingbee.com, so your reviewers can check it directly rather than taking our word for it.
    • No. Our default engagement model does not connect into your systems, so no API or system integration is required. We work from data you send us through a secure transfer. If you would prefer an integration, we can scope one, but nothing about the standard engagement depends on it.

    Security controls and compliance

    • Flowing Bee is SOC 2 compliant and independently audited. Type I is attested and the Type II audit is in progress. We are also penetration tested at least annually by an independent third party, and our controls are monitored continuously in between.
    • Our controls are monitored continuously rather than checked once a year:
      • Ongoing vulnerability and system monitoring across our infrastructure and dependencies.
      • Annual independent penetration testing.
      • Annual control self-assessments, alongside change management and a defined software development lifecycle.
      Identified vulnerabilities are triaged by severity and tracked through to remediation.
    • We maintain an Incident Response Plan, along with business continuity and disaster recovery plans that are tested annually. We also hold cybersecurity insurance, and our board is briefed on cyber risk annually.
    • Yes. We have completed security due diligence with large enterprise clients across several sectors. We do not name clients without their consent, so rather than take our word for it, point your InfoSec team at our trust centre for direct visibility into our security posture: trust.flowingbee.com

    Personal information (PII) and access

    • This varies by brief and is agreed in scope before work begins. We prefer de-identified or aggregated data wherever the work allows. Common data types include:
      • De-identified customer survey or behavioural data.
      • Campaign performance data.
      • Anonymised CRM segments.
      • Interview transcripts.
      We do not collect credit-card data, and we do not collect personal health information.
    • We ask that you share personally identifiable information only where it is genuinely necessary for your engagement. Where you do:
      • It is encrypted in transit and at rest.
      • Access is role-based and restricted to the people who need it.
      • It is covered by our data classification, retention and disposal procedures.
      • Your data is deleted when you leave.
      Our handling of personal information follows the Australian Privacy Act 1988 and the Australian Privacy Principles.
    • Staff and contractors are background checked and sign confidentiality agreements before any data is shared, and are bound by our code of conduct. Access is granted at the minimum level necessary, privileged access is restricted, and access is revoked on termination.

    Questions we haven't answered here?

    Start a conversation