Trust center

Security at GuestFlow

GuestFlow is built for podcast teams who handle guest PII, calendar access, and recording logistics every day. We follow the same principles enterprise schedulers like Calendly publish — encryption, access control, audit visibility, and privacy by design — at a stage appropriate for a focused scheduling product.

Customer data protection

  • Logical tenant separation

    In place

    Every host account is isolated with Supabase Row Level Security on all application tables. Team members inherit scoped access through role-based policies.

  • Encryption in transit

    In place

    All traffic is served over HTTPS (TLS 1.2+). OAuth integration flows use httpOnly state cookies.

  • Encryption at rest

    In place

    Database and object storage are encrypted at rest by our infrastructure providers (Supabase Postgres, Cloudflare R2).

  • Domain control

    Planned

    Verified corporate domains and centralized IT-managed onboarding — on the Agency roadmap.

Infrastructure security

  • Cloud hosting

    In place

    GuestFlow runs on Vercel (application) and Supabase (database, auth, storage). Payments are processed by Stripe.

  • DDoS mitigation

    In place

    Platform-level DDoS protection is included with Vercel hosting on all plans.

  • Network perimeter

    In place

    Database access is not exposed publicly; only the Supabase API gateway is reachable with scoped keys.

Application protection

  • Security headers

    In place

    HSTS, X-Content-Type-Options, Referrer-Policy, and frame protections are applied on dashboard and marketing routes.

  • Webhook verification

    In place

    Stripe webhooks are verified with signature checks before any billing state changes.

  • Rate limiting & bot protection

    In progress

    Public booking endpoints are being hardened with Vercel Firewall rate limits and bot challenges.

  • Penetration testing

    Planned

    Third-party security assessments are planned ahead of enterprise sales.

Compliance & privacy

  • GDPR & CCPA

    In place

    Privacy policy, lawful bases, subprocessors, and data subject rights are documented. Hosts export or delete account data from Settings → Privacy.

  • Recording & marketing consent

    In place

    Booking flows capture explicit consent for recording and optional marketing follow-up.

  • SOC 2 / ISO 27001

    Planned

    We do not yet hold formal certifications. Subprocessor and security documentation is available on request for Agency customers.

  • Data processing agreement

    Planned

    Standard DPA for hosts acting as controllers — available on request.

Account protection

  • Role-based admin access

    In place

    Studio and Agency plans include team roles (Admin, Editor, Viewer), seat limits, groups, and an audit trail for invites and brief actions.

  • Activity audit log

    In place

    Account owners and team admins can review recent team and brief activity from the Admin hub.

  • PII deletion

    In place

    Hosts can permanently delete their account and associated data from the dashboard (Settings → Privacy).

  • SSO & SCIM

    Planned

    Enterprise SSO (SAML/OIDC) and automated user provisioning — Agency+ roadmap.

  • Multi-factor authentication

    Planned

    MFA enrollment for host accounts is on the near-term roadmap.

Report a security issue

If you believe you've found a vulnerability in GuestFlow, please email security@guestflow.app. Include steps to reproduce and any proof-of-concept. We aim to acknowledge reports within two business days.

See also our Privacy Policy and Terms of Service.