Security

Security Overview

How OptiFlow Labs hosts, secures, and operates the FailSafe platform. A single document for prospects, customers, and partners covering encryption, access controls, tenancy isolation, data retention, the service providers we rely on, and where we are on the compliance roadmap.

Effective
May 13, 2026
Last updated
May 13, 2026

01Overview

FailSafe is a SaaS platform that connects to Microsoft 365 and Google Workspace tenants using read only API access. We use that access to discover unsanctioned tools, third party app permissions, identity risks, and license assignments, then surface the findings in the portal and in a PDF report.

Because the data we look at is sensitive, we have designed FailSafe to read the minimum necessary, store it under tenancy isolation, encrypt it at rest and in transit, and let you revoke access at any time.

Operating Principles

Read only access by design. No write permissions are requested from any customer tenant. Tenancy scoped queries on every customer facing endpoint. Audit logged admin actions. US hosted. No customer data is used to train AI models.

02Hosting and Data Residency

FailSafe runs on Railway, a US based cloud platform that provides our application hosting and managed PostgreSQL database. All production infrastructure is located in the United States.

We do not replicate customer data to regions outside the United States. If you operate from outside the US and access the service, your data will be transferred to and processed in the United States as described in our Privacy Policy.

03Encryption

In transit

Every customer connection to portal.optiflowlabs.ai, optiflowlabs.ai, and the FailSafe API runs over TLS 1.2 or higher. HSTS is enabled. Internal connections between the application and the managed PostgreSQL database also use TLS.

At rest

04Authentication and Access Controls

Customer authentication

Role based access in the portal

FailSafe has three roles: client (the customer business viewing its own engagement), admin (internal OptiFlow Labs staff), and partner (managed service provider managing client engagements on behalf of an SMB). Every customer facing API endpoint runs an engagement access check before returning data, scoped to the actor's role and to the engagement they are permitted to see.

Account deletion

Customers can request account deletion from the portal. Deletion runs as a soft delete first (data marked for removal, Stripe subscription cancelled), then a nightly job at 04:00 UTC hard deletes the underlying records and report files. Audit log entries are retained for the period described in section 07.

05Internal Access at OptiFlow Labs

OptiFlow Labs operates as a small team. Production access is limited accordingly.

06Tenancy Isolation

FailSafe is multi tenant by design with logical isolation between customer engagements.

07Data Retention and Deletion

You can request early deletion of your engagement or account at any time by emailing privacy@optiflowlabs.ai. The full Privacy Policy is at optiflowlabs.ai/privacy.

08Service Providers

The following service providers handle data on our behalf in support of the FailSafe platform. Each is contractually bound to use the data only for the services they provide to us, and each is hosted in the United States.

Microsoft and Google APIs (Microsoft Graph and the Google Admin SDK and Gmail API) are not service providers to OptiFlow Labs. They are the customer's own tenant systems, accessed under credentials the customer authorized. We pull data from those systems on the customer's behalf and persist it in our database as described above.

09Incident Response

We treat any unauthorized access to customer data, loss of integrity of customer data, or material service outage as a security incident.

Security reports and vulnerability disclosures are welcome at security@optiflowlabs.ai.

10Vulnerability Management

11Compliance Roadmap

FailSafe is not currently SOC 2 attested. We operate today with controls aligned to the SOC 2 trust services criteria, and our intent is to pursue SOC 2 Type 1 in 2027 once the customer base supports the audit and tooling investment.

The frameworks that customers most often map us against, and that we map our own reports to:

Customers running FailSafe receive a posture report mapped to these frameworks. The mapping is part of every engagement deliverable.

12What We Do Not Have Yet

We are an early stage platform. We list the gaps openly because pretending otherwise is worse than naming them.

13Contact

If you have questions about this Security Overview, need a vendor security questionnaire completed, or want to report a vulnerability, please contact us:

Entity
OptiFlow Labs LLC
Security and general
security@optiflowlabs.ai
Privacy
privacy@optiflowlabs.ai
Billing
billing@optiflowlabs.ai
Website
www.optiflowlabs.ai