Trust center
Security at GuestFlow
GuestFlow is built for podcast teams who handle guest PII, calendar access, and recording logistics every day. We follow the same principles enterprise schedulers like Calendly publish — encryption, access control, audit visibility, and privacy by design — at a stage appropriate for a focused scheduling product.
Customer data protection
Logical tenant separation
In placeEvery host account is isolated with Supabase Row Level Security on all application tables. Team members inherit scoped access through role-based policies.
Encryption in transit
In placeAll traffic is served over HTTPS (TLS 1.2+). OAuth integration flows use httpOnly state cookies.
Encryption at rest
In placeDatabase and object storage are encrypted at rest by our infrastructure providers (Supabase Postgres, Cloudflare R2).
Domain control
PlannedVerified corporate domains and centralized IT-managed onboarding — on the Agency roadmap.
Infrastructure security
Cloud hosting
In placeGuestFlow runs on Vercel (application) and Supabase (database, auth, storage). Payments are processed by Stripe.
DDoS mitigation
In placePlatform-level DDoS protection is included with Vercel hosting on all plans.
Network perimeter
In placeDatabase access is not exposed publicly; only the Supabase API gateway is reachable with scoped keys.
Application protection
Security headers
In placeHSTS, X-Content-Type-Options, Referrer-Policy, and frame protections are applied on dashboard and marketing routes.
Webhook verification
In placeStripe webhooks are verified with signature checks before any billing state changes.
Rate limiting & bot protection
In progressPublic booking endpoints are being hardened with Vercel Firewall rate limits and bot challenges.
Penetration testing
PlannedThird-party security assessments are planned ahead of enterprise sales.
Compliance & privacy
GDPR & CCPA
In placePrivacy policy, lawful bases, subprocessors, and data subject rights are documented. Hosts export or delete account data from Settings → Privacy.
Recording & marketing consent
In placeBooking flows capture explicit consent for recording and optional marketing follow-up.
SOC 2 / ISO 27001
PlannedWe do not yet hold formal certifications. Subprocessor and security documentation is available on request for Agency customers.
Data processing agreement
PlannedStandard DPA for hosts acting as controllers — available on request.
Account protection
Role-based admin access
In placeStudio and Agency plans include team roles (Admin, Editor, Viewer), seat limits, groups, and an audit trail for invites and brief actions.
Activity audit log
In placeAccount owners and team admins can review recent team and brief activity from the Admin hub.
PII deletion
In placeHosts can permanently delete their account and associated data from the dashboard (Settings → Privacy).
SSO & SCIM
PlannedEnterprise SSO (SAML/OIDC) and automated user provisioning — Agency+ roadmap.
Multi-factor authentication
PlannedMFA enrollment for host accounts is on the near-term roadmap.
Report a security issue
If you believe you've found a vulnerability in GuestFlow, please email security@guestflow.app. Include steps to reproduce and any proof-of-concept. We aim to acknowledge reports within two business days.
See also our Privacy Policy and Terms of Service.
