Security

Limit access. Keep records small. Fail closed.

AgencyFlow measures conversation response timing while discarding message content and contact details before background processing.

Report a security concern →

Protection at each part of the request path.

These controls describe the deployed development environment. We update this page when material data flows or safeguards change.

01

HTTPS only

Website, installation, callback, webhook, and application traffic use encrypted HTTPS connections.

02

Managed encryption

OAuth tokens, queues, database records, notifications, and secret values use AWS-managed encryption at rest.

03

Restricted credentials

OAuth secrets stay in Secrets Manager. Application roles can read only the specific secret or service resource required for their job.

04

Short-lived sessions

The embedded dashboard exchanges signed context for a five-minute session kept in page memory rather than browser storage.

05

Verified events

Webhook authenticity is checked before processing. Duplicate events are rejected, and downstream work runs through a bounded queue.

06

Redacted logs

Logs exclude access tokens, refresh tokens, authorization codes, authentication headers, full webhook bodies, and application-form contents.

Store the response signal, not the conversation.

AgencyFlow stores installation metadata, granted permissions, client-account identifiers, normalized channel, timestamps, response status, and one-way hashes of contact and conversation identifiers.

Message bodies, names, email addresses, phone numbers, sender and recipient fields, attachments, and full webhook payloads are not retained.

Read the full Privacy Policy →

Infrastructure with a defined role.

Amazon Web Services hosts the API, functions, database, queues, secret storage, operational logs, and pilot-application notification. Cloudflare provides website delivery, DNS, TLS, and network security.

Send enough detail to reproduce the issue, never live credentials.

Email hello@constructlabs.io with the affected URL, observed behavior, time, and safe reproduction steps.

Do not include passwords, authorization codes, access tokens, refresh tokens, API keys, customer records, or active exploit traffic. We will acknowledge a credible report as soon as practical and coordinate testing before public disclosure.

Security contact

Found something we should investigate?

Send a report ↗