Your fabrication data is the backbone of your business — and we treat it that way. Here’s exactly how we protect your shop floor data, customer records, and intellectual property. We don’t claim certifications we haven’t earned; this page reflects what we actually do, today.
Encryption
All traffic is encrypted in transit with SSL/TLS (HTTPS everywhere). Backups are encrypted with AES-256 before they leave the server.
Encrypted Daily Backups
Your database is backed up every day and encrypted with AES-256. Backups are retained for 30 days and stored off-server.
Role-Based Access
Admin, manager, and shop floor roles with granular permissions — a welder sees work orders and time clock, the owner sees everything.
Audit Logs
Logins and access events are recorded. Every quote, work order, and change carries its own history.
How We Protect Your Data
- Transport encryption. All traffic between your browser and FabFlow is encrypted with SSL/TLS. Plain HTTP is not available.
- Encrypted backups with 30-day retention. The production database is backed up nightly. Each archive is encrypted with AES-256 and the encryption key is stored separately from the backups.
- Role-based access control. Admin, manager, and shop floor roles restrict what each user can see and do. Shop floor users get a PIN-based kiosk login with limited scope.
- Audit logging. Logins are recorded, and every change to quotes, work orders, and inventory is attributable to a user.
- Full data export. Export everything — quotes, work orders, customers, inventory, timeclock — as JSON from your account page, any time.
- Account deletion. Delete your account and all of your tenant’s data permanently from the account page. No lock-in, no waiting.
Your Data Rights
Your data belongs to you. You can export a complete JSON copy of your shop’s data from the account page at any time, and you can permanently delete your account and all associated data — a self-service operation that cascades through every table. We don’t sell your data, and we don’t use your shop’s data to train third-party models.
Responsible Disclosure
We welcome responsible disclosure of security vulnerabilities. If you believe you’ve found a security issue, please email security@fabflowpro.com. We will acknowledge your report and provide a status update. We do not retaliate against researchers who follow responsible disclosure practices.