SECURITY AT MELLOFLO

Trust deserves
clear answers.

Security is not a badge in a footer. It is how MelloFlo limits access, protects sensitive information, verifies requests and keeps you in control of connected services.

Last reviewed 9 September 2026Applies to MelloFlo web app and connected channels
i

OUR CURRENT ASSURANCE STATUS

No borrowed badges. No premature claims.

MelloFlo does not currently claim ISO 27001 or SOC 2 certification, an independent penetration-test attestation, or a completed formal GDPR compliance assessment. Those assurance activities require evidence and independent review. We will publish verified status only when the relevant work is complete.

HOW WE THINK ABOUT SECURITY

Protect the action, the context and the person.

MelloFlo works across communication and productivity tools, so its security model starts with restraint: request narrow permissions, encrypt specified sensitive fields, isolate each user’s records, and ask for confirmation before meaningful actions.

01

Application-layer encryption

Specified sensitive fields and OAuth refresh tokens are encrypted using AES-256-GCM. Token ciphertext is bound to its user and record context to help prevent substitution between records.

02

Protected transport

MelloFlo is served over HTTPS. Strict transport and browser security headers help reduce downgrade, framing, content-injection and cross-origin risks.

03

Secure sessions

Browser sessions use Secure, HttpOnly, host-only cookies with SameSite protection. Session tokens are stored as hashes rather than readable credentials.

04

User and tenant isolation

Application queries are scoped to the signed-in user. Automated negative tests check that one account cannot retrieve, alter or delete another account’s records.

05

Verified inbound requests

Supported webhooks use provider signature verification. Rate limits and exact-origin checks protect sensitive endpoints and state-changing browser requests.

06

Confirmation-first actions

MelloFlo asks you to review externally meaningful actions—such as a calendar event or a reminder created from Slack—before the action is committed.

NARROW BY DEFAULT

Each connection gets only the access its feature needs.

You can connect or disconnect every optional integration from MelloFlo Settings.

Gmail

Read-only access for visible email signals. MelloFlo cannot send, delete, move or modify your Gmail messages.

gmail.readonly
Google Drive

Limited to files MelloFlo creates or files you explicitly select for MelloFlo.

drive.file
Google Calendar

Limited to events owned by you, with confirmation before event creation.

events.owned
Slack

The message shortcut sends only the message you deliberately choose into the reminder flow.

commands

YOUR DATA, YOUR DECISION

Controls that stay within reach.

Review and correct

View reminders and saved memory, then update or remove information that is no longer useful or accurate.

Disconnect integrations

Revoke an optional connection from Settings. Disconnecting stops future access through that integration.

Export and delete

Request an export of available account information or initiate account deletion after recent identity verification.

Minimised operational records

Security audit records use structured allowlisted fields designed to avoid message bodies, secrets and full connected-service content.

TRANSPARENCY INCLUDES LIMITS

What we are still strengthening.

In progress

Independent assessment

Formal third-party penetration testing and certification assessment have not yet been completed.

In progress

Operational evidence

We are continuing to mature documented key-rotation, recovery, monitoring and incident-response exercises.

In progress

Policy finalisation

Detailed retention schedules and provider-verification work are being completed before broader release.

No online service can promise absolute security. If we identify a material issue, our priority is containment, investigation, recovery and clear communication to affected users where required.

REPORT A SECURITY CONCERN

Tell us privately.

Please include the affected page or feature, steps to reproduce, expected impact and a safe way to contact you. Do not include passwords, OAuth tokens or another person’s private data.

Email the MelloFlo team ↗