Security

Built to be trusted with something you didn't have to give us.

You're handing CostFlow an API token into your team's work-tracking system. Here's exactly what we do with it, and what we never do.

Read-only, always

CostFlow connects to Jira and ClickUp with a personal API token you provide, and it only reads. It doesn't write comments, change statuses, move tickets, or touch your board in any way. Revoke the token and the connection stops working immediately. That's the whole mechanism; there's no separate opt-out to remember.

Credentials, encrypted

Your API token is encrypted at rest. Nobody at CostFlow can read it back out in plain text once it's saved, including us. It's used exactly once per analysis run, to fetch your data, and then it's done.

People aren't the product

Every individual in your imported data is pseudonymized before analysis runs. No report, export, or dashboard ranks or scores a named person. Cost is attributed to processes and stages, queues, delays, overdue work, not to whoever happened to touch the ticket.

To be precise about what that does and doesn't mean: we do store assignee names as your tracker shows them, in your workspace configuration, because the setup flow asks you to map people to roles and you need to recognise who you're mapping. Those names are never an input to the analysis and never reach a report. A guard checks the rendered bytes of every report against the identities in your own data and withholds the report rather than serve one that names somebody.

Your organization's data stays yours

Every organization's data is isolated from every other organization's. There's no cross-tenant reporting, no aggregate benchmarking that mixes your numbers with someone else's, and no way for another CostFlow customer to see anything about your workspace.

We don't track you to sell you anything

CostFlow ships with no third-party analytics, no ad trackers, no session replay tools. The strict content policy on every page blocks third-party scripts outright. It's not a settings toggle; it's how the app is built. What little product analytics we keep is aggregate counts, like how many organizations reach a given step, never your content.

Delete anytime, actually

You can delete a workspace or your entire organization whenever you want. Deletion cascades to every report derived from that data. We don't keep a "just in case" copy.

Where we're headed

CostFlow is a beta product from a small team. We haven't gone through a formal SOC 2 audit yet. We're building toward that as the product and the team grow, and we'll say so here the moment it's real rather than before. If your security team needs something specific to evaluate us, a data flow diagram, a subprocessor list, answers to a vendor questionnaire, email us and we'll get it to you directly.

Questions before you connect? support@fbx1.com