Security principles
Flow Batch Studio is designed with account isolation, protected authentication, secure transport, input validation, and operational logging in mind. Security controls are continuously subject to change as the product and infrastructure evolve.
- HTTPS is used for the production website and OAuth production flows.
- Account-scoped authorization checks are used around authenticated application data.
- Passwords are processed using protected password-hashing mechanisms rather than being stored as plain text.
- OAuth credentials and tokens are treated as sensitive credentials and are not intended to be exposed through project content or support requests.
- Uploaded media is validated before being accepted by supported upload endpoints.
Account security
Choose a unique password, keep your email account secure, and do not share your Flow Batch Studio credentials. If you use Google authentication, protect the Google account used to authorize the service.
If you suspect unauthorized access, change your password where applicable, revoke suspicious Google/YouTube access, and contact us promptly.
Third-party providers
Some functionality depends on hosting, storage, email, AI/model, media-generation, authentication, and publishing providers. A provider outage or security incident can affect a feature even when the Flow Batch Studio application itself remains available.
Connected-provider access is limited to the permissions required for the feature you authorize, subject to the provider's own policies and technical behavior.
Responsible disclosure
Please report suspected vulnerabilities privately through the contact page. Include affected URL or feature, reproduction steps, impact, and any safe proof of concept. Do not access, modify, delete, or disclose another user's data.
We may acknowledge reports, request additional information, and coordinate remediation. Do not publicly disclose an unresolved vulnerability before giving us a reasonable opportunity to investigate.
Security limitations
No online service can guarantee absolute security. Users are responsible for securing their own devices, email accounts, connected Google accounts, API keys, and third-party accounts. Third-party services are governed by their own security practices and terms.