Security
Your data, looked after.
How we protect your account and your data, and how to tell us if you find a problem.
Draft for review. This document has not been finalised and may change before launch.
Encryption
All traffic uses TLS. Data is encrypted at rest.
Access control
Staff access to customer data is limited, logged and reviewed. Placeholder.
Backups
Data is backed up daily and restores are tested. Placeholder.
Your account
Two-factor authentication, and SSO on Enterprise plans. Placeholder.
Last updated 8 October 2026
Reporting a vulnerability
We welcome reports from security researchers and customers. If you think you’ve found a vulnerability in Flowershift, please tell us so we can fix it.
Email security@flowershift.com.au with:
- A description of the issue and where you found it
- Steps to reproduce it
- What an attacker could do with it
Our contact details are also in our security.txt file.
What to expect
- We’ll acknowledge your report within 3 business days.
- We’ll keep you updated while we investigate and fix it.
- With your permission, we’ll credit you once it’s fixed.
Please don’t
- Access, change or delete other people’s data
- Run denial-of-service or automated high-volume testing
- Use social engineering or physical attacks
- Make the issue public before we’ve had a reasonable time to fix it
If you act in good faith and follow this policy, we won’t take legal action against you for your research.
