Security
Automated decisions, kept secure.
The uFlow decision engine applies multiple layers of security designed to protect data, safeguard the confidentiality of information and support business continuity.
Cloud infrastructure
The infrastructure is hosted in the cloud with advanced physical and logical security measures, secure data centers, strict access control and constant monitoring. The serverless architecture is redundant across multiple availability zones.
Authentication and authorization
- Two-factor authentication (2FA) for account access.
- Attribute-based access control (ABAC) with specific roles and permissions.
- API access through JWT tokens, with controlled expiry and renewal.
Data encryption
- Data at rest: all stored information is encrypted.
- Data in transit: communication over secure protocols (HTTPS/TLS).
- Cryptographic validation tokens instead of credentials in messaging.
Threat protection
- Intrusion prevention systems that detect malicious activity.
- Continuous network monitoring for anomalies, with immediate response.
- ISO/IEC 27001:2022 certification. The platform is aligned with PCI DSS and to cloud architecture best-practice frameworks.
Backup and recovery
We run periodic backups stored in geographically dispersed locations, with a recovery point objective (RPO) of under 5 minutes in disaster scenarios.
Vendor assessment and due diligence
If your organization is evaluating uFlow as a vendor, we share our security documentation under a confidentiality agreement and answer due diligence questionnaires. Our team supports the technical, security and procurement review stages your process requires.
- Security documentation and certification scope available under NDA.
- Responses to vendor assessment and security questionnaires.
- Support from the uFlow team throughout the review.
Security and governance, not just security
For a bank, protecting the data is the baseline. Controlling who changes what, and holding evidence of every decision, is what the regulator asks for.
Traceability and audit
Every decision records its input, the rules applied and the outcome. Search and export transactions for audit and compliance.
Read the guideRole segregation and secrets
Per-user permissions, API key management and credentials stored as secrets — never inside the policies themselves.
Read the guideVersioning and change control
Every version of every policy is kept; an earlier one can be reactivated instantly if an incident calls for it.
Read the guideISO/IEC 27001:2022 certification
In May 2024 our decision engine earned ISO/IEC 27001:2022 certification, the international standard for information security, aimed at protecting our customers’ data.


ISO/IEC 27001:2022 is our only formal certification. The platform is aligned with PCI DSS and with cloud architecture best-practice frameworks.
What happens when something fails
A credit decision is a critical process: if the engine does not respond, origination stops. This is what holds continuity up, and what you can verify.
Committed availability
99.95% SLA. The platform’s observed average availability runs above it: 99.995%.
Backups and monitoring
High-availability infrastructure with geographically distributed backups and continuous monitoring, on a serverless AWS architecture.
Roll back in minutes
When a change goes wrong there is no deployment to wait for: the previous version of the policy is reactivated in a controlled way. Operational recovery is immediate.
Regular penetration testing
We run periodic audits with penetration testing and code analysis, on top of the ISO/IEC 27001:2022 certification cycle.
Nothing is tested in production
Environments are separated: a policy goes through design, testing and correction before it touches a real application.
Every decision is on the record
After an incident you can reconstruct which policy was live, which data was queried and why it resolved the way it did.
The details, under a confidentiality agreement
The full continuity plan, the recovery objectives (RTO and RPO), the scope of the certification and the reference architecture are part of the evaluation package, shared with the team running due diligence. They are not published here because every institution reviews them against its own requirements.
See the evaluation packageEverything you need to know
How does uFlow protect data security?+
uFlow applies layered security: cloud infrastructure with a redundant serverless architecture, encryption at rest and in transit (HTTPS/TLS), 2FA authentication, ABAC access control and cryptographic validation tokens.
Does uFlow comply with recognized security standards?+
uFlow holds the ISO/IEC 27001:2022 certification — its only certification — and is aligned with PCI DSS and to cloud architecture best-practice frameworks. Security is also subject to periodic reviews within the ISMS.
What happens to my data in a disaster scenario?+
uFlow runs periodic, geographically dispersed backups with a recovery point objective of under 5 minutes of data loss in disaster recovery scenarios.
Does uFlow respect user privacy?+
The confidentiality of information is protected within the Information Security Management System (ISMS) certified under ISO/IEC 27001:2022, and data is processed in accordance with the agreements signed with each client.
Can I access the security documentation for a due diligence process?+
Yes. We share our security documentation and the scope of the ISO/IEC 27001:2022 certification under a confidentiality agreement, and we answer vendor assessment questionnaires. You can request it from the contact page.
Need our security documentation?
We review how you decide today and show you how it would work in the engine, with your own sources and policies.



