Security at Flo
Last updated: August 6, 2026
Flo is designed to keep workspace collaboration separated, access controlled, and important capture and amplification actions visible.
How we protect your workspace
Workspace-bound access
Live sessions, moments, outcomes, memory, followups, meeting context, and connected providers are associated with a specific workspace. Protected requests are authenticated and checked against workspace membership before data is returned.
Roles and permissions
Workspace owners and admins manage membership, billing, provider connections, AI posture, retention, exports, and other elevated controls. Members work within the access granted to their workspace role.
Protected files and meeting artifacts
Recordings, transcripts, and uploaded artifacts use authenticated application flows. Private file access uses short-lived signed links where supported, limiting how long a file URL remains usable.
Authentication and credentials
Passwords are stored using one-way hashing. Authenticated sessions use signed tokens, and sensitive routes require authorization checks.
Connected-provider credentials and AI keys are encrypted before storage. Flo does not display raw provider secrets to workspace users.
Meeting sources
Flo uses scoped authorization for Zoom, Microsoft Teams, and Google Meet connections. Each workspace approves its own connection, provider account, and requested permissions.
OAuth connection flows use expiring state records. Meeting import is limited to the meetings available to the connected account and the access approved by the workspace.
AI and amplification
Workspace controls can allow platform AI, a workspace-owned provider key, or disabled AI processing. AI output should be reviewed before it is used for consequential decisions.
Flo remains useful on its own. Moving a captured moment into Taskologic is explicit and permissioned; Flo does not silently create structured Taskologic work.
Recording, transcription, and consent
Flo is designed to make recording and transcription state visible. Customers are responsible for giving required notice, obtaining consent, and configuring workspace policies appropriate for their participants and jurisdiction.
Review the Recording & Consent Disclosure before recording or transcribing a session.
Monitoring and accountability
Flo records supported workspace, provider, billing, AI, and data-control activity. Rate limits protect sensitive authentication, integration, and operational endpoints from excessive use.
We investigate suspected security incidents and notify affected customers when required by applicable law or contractual commitments.
Infrastructure and service providers
Flo uses established infrastructure providers for application hosting, storage, communications, payments, meetings, and AI processing. Data is protected in transit using HTTPS where supported by the service path, with additional safeguards provided by the underlying vendors.
Third-party services connected by a customer remain subject to that provider’s security, privacy, and availability practices.
Current compliance posture
Flo maintains security, privacy, AI disclosure, acceptable-use, recording-consent, and data-processing documentation. Formal certifications and additional enterprise controls are tracked separately in our Compliance Roadmap.
Flo does not currently represent itself as SOC 2 certified.
Your role
Customers are responsible for managing workspace membership, protecting account credentials, reviewing provider permissions, configuring data and AI controls, and obtaining required consent before recording or processing meetings.
Report unexpected access, suspected misuse, or a security concern as soon as possible.
Contact
Security inquiries and responsible disclosures: support@taskologic.com
Privacy requests: support@taskologic.com