Skip to content
Decision engine

Security

Automated decisions, kept secure.

The uFlow decision engine applies multiple layers of security designed to protect data, safeguard the confidentiality of information and support business continuity.

Cloud infrastructure

The infrastructure is hosted in the cloud with advanced physical and logical security measures, secure data centers, strict access control and constant monitoring. The serverless architecture is redundant across multiple availability zones.

Authentication and authorization

  • Two-factor authentication (2FA) for account access.
  • Attribute-based access control (ABAC) with specific roles and permissions.
  • API access through JWT tokens, with controlled expiry and renewal.

Data encryption

  • Data at rest: all stored information is encrypted.
  • Data in transit: communication over secure protocols (HTTPS/TLS).
  • Cryptographic validation tokens instead of credentials in messaging.

Threat protection

  • Intrusion prevention systems that detect malicious activity.
  • Continuous network monitoring for anomalies, with immediate response.
  • ISO/IEC 27001:2022 certification. The platform is aligned with PCI DSS and to cloud architecture best-practice frameworks.

Backup and recovery

We run periodic backups stored in geographically dispersed locations, with a recovery point objective (RPO) of under 5 minutes in disaster scenarios.

Vendor assessment and due diligence

If your organization is evaluating uFlow as a vendor, we share our security documentation under a confidentiality agreement and answer due diligence questionnaires. Our team supports the technical, security and procurement review stages your process requires.

  • Security documentation and certification scope available under NDA.
  • Responses to vendor assessment and security questionnaires.
  • Support from the uFlow team throughout the review.
Certifications

ISO/IEC 27001:2022 certification

In May 2024 our decision engine earned ISO/IEC 27001:2022 certification, the international standard for information security, aimed at protecting our customers’ data.

ISO/IEC 27001:2022 information security certificationIQNET certification mark
ISO/IEC 27001:2022 · Certified
Aligned with
PCI DSSCloud architecture best practicesHTTPS / TLS2FAEncryption at rest

ISO/IEC 27001:2022 is our only formal certification. The platform is aligned with PCI DSS and with cloud architecture best-practice frameworks.

Continuity

What happens when something fails

A credit decision is a critical process: if the engine does not respond, origination stops. This is what holds continuity up, and what you can verify.

Committed availability

99.95% SLA. The platform’s observed average availability runs above it: 99.995%.

Backups and monitoring

High-availability infrastructure with geographically distributed backups and continuous monitoring, on a serverless AWS architecture.

Roll back in minutes

When a change goes wrong there is no deployment to wait for: the previous version of the policy is reactivated in a controlled way. Operational recovery is immediate.

Regular penetration testing

We run periodic audits with penetration testing and code analysis, on top of the ISO/IEC 27001:2022 certification cycle.

Nothing is tested in production

Environments are separated: a policy goes through design, testing and correction before it touches a real application.

Every decision is on the record

After an incident you can reconstruct which policy was live, which data was queried and why it resolved the way it did.

The details, under a confidentiality agreement

The full continuity plan, the recovery objectives (RTO and RPO), the scope of the certification and the reference architecture are part of the evaluation package, shared with the team running due diligence. They are not published here because every institution reviews them against its own requirements.

See the evaluation package
Frequently asked questions

Everything you need to know

How does uFlow protect data security?+

uFlow applies layered security: cloud infrastructure with a redundant serverless architecture, encryption at rest and in transit (HTTPS/TLS), 2FA authentication, ABAC access control and cryptographic validation tokens.

Does uFlow comply with recognized security standards?+

uFlow holds the ISO/IEC 27001:2022 certification — its only certification — and is aligned with PCI DSS and to cloud architecture best-practice frameworks. Security is also subject to periodic reviews within the ISMS.

What happens to my data in a disaster scenario?+

uFlow runs periodic, geographically dispersed backups with a recovery point objective of under 5 minutes of data loss in disaster recovery scenarios.

Does uFlow respect user privacy?+

The confidentiality of information is protected within the Information Security Management System (ISMS) certified under ISO/IEC 27001:2022, and data is processed in accordance with the agreements signed with each client.

Can I access the security documentation for a due diligence process?+

Yes. We share our security documentation and the scope of the ISO/IEC 27001:2022 certification under a confidentiality agreement, and we answer vendor assessment questionnaires. You can request it from the contact page.

Need our security documentation?

We review how you decide today and show you how it would work in the engine, with your own sources and policies.