Security at Flo

Last updated: August 6, 2026

Flo is designed to keep workspace collaboration separated, access controlled, and important capture and amplification actions visible.


How we protect your workspace

Workspace-bound access

Live sessions, moments, outcomes, memory, followups, meeting context, and connected providers are associated with a specific workspace. Protected requests are authenticated and checked against workspace membership before data is returned.

Roles and permissions

Workspace owners and admins manage membership, billing, provider connections, AI posture, retention, exports, and other elevated controls. Members work within the access granted to their workspace role.

Protected files and meeting artifacts

Recordings, transcripts, and uploaded artifacts use authenticated application flows. Private file access uses short-lived signed links where supported, limiting how long a file URL remains usable.

Authentication and credentials

Passwords are stored using one-way hashing. Authenticated sessions use signed tokens, and sensitive routes require authorization checks.

Connected-provider credentials and AI keys are encrypted before storage. Flo does not display raw provider secrets to workspace users.

Meeting sources

Flo uses scoped authorization for Zoom, Microsoft Teams, and Google Meet connections. Each workspace approves its own connection, provider account, and requested permissions.

OAuth connection flows use expiring state records. Meeting import is limited to the meetings available to the connected account and the access approved by the workspace.

AI and amplification

Workspace controls can allow platform AI, a workspace-owned provider key, or disabled AI processing. AI output should be reviewed before it is used for consequential decisions.

Flo remains useful on its own. Moving a captured moment into Taskologic is explicit and permissioned; Flo does not silently create structured Taskologic work.

Recording, transcription, and consent

Flo is designed to make recording and transcription state visible. Customers are responsible for giving required notice, obtaining consent, and configuring workspace policies appropriate for their participants and jurisdiction.

Review the Recording & Consent Disclosure before recording or transcribing a session.

Monitoring and accountability

Flo records supported workspace, provider, billing, AI, and data-control activity. Rate limits protect sensitive authentication, integration, and operational endpoints from excessive use.

We investigate suspected security incidents and notify affected customers when required by applicable law or contractual commitments.

Infrastructure and service providers

Flo uses established infrastructure providers for application hosting, storage, communications, payments, meetings, and AI processing. Data is protected in transit using HTTPS where supported by the service path, with additional safeguards provided by the underlying vendors.

Third-party services connected by a customer remain subject to that provider’s security, privacy, and availability practices.

Current compliance posture

Flo maintains security, privacy, AI disclosure, acceptable-use, recording-consent, and data-processing documentation. Formal certifications and additional enterprise controls are tracked separately in our Compliance Roadmap.

Flo does not currently represent itself as SOC 2 certified.

Your role

Customers are responsible for managing workspace membership, protecting account credentials, reviewing provider permissions, configuring data and AI controls, and obtaining required consent before recording or processing meetings.

Report unexpected access, suspected misuse, or a security concern as soon as possible.

Contact

Security inquiries and responsible disclosures: support@taskologic.com

Privacy requests: support@taskologic.com