Security & Trust

StockFlow security posture: encryption, warehouse permissions, GDPR, vulnerability disclosure, and an honest view of SSO, MFA, and certification status.

Security & Trust

How StockFlow protects your inventory data—and what we do and do not claim for regulated buyers.

By Tibeau De Grauwe, FounderUpdated July 2026

  • 25 products free
  • No credit card
  • 10-min setup
Honest security posture for growing and regulated ops

Built for accountability—without overclaiming certifications

StockFlow helps teams track stock and assets across locations with clear access control and history. Public-sector, defense-adjacent, and security buyers deserve an accurate picture of what ships today versus what is still on the roadmap.

Available today

Practical controls that support multi-site inventory and asset accountability for SMBs, municipalities, and defense-adjacent contractors.

Encryption in transit and at rest

TLS for data in transit. Cloud database encryption at rest on our hosting provider.

Warehouse roles and permissions

Owner, admin, and staff presets with granular keys for scanning, adjustments, product edits, exports, and team management.

Movement and asset history

Stock movements and asset check-in/check-out records include who acted and when, supporting day-to-day accountability.

GDPR and EU company posture

StockFlow is based in Belgium and designed with GDPR obligations in mind. See /gdpr for product-level findings (export, deletion, gaps) and the Privacy Policy for the legal notice.

Vulnerability disclosure

Responsible disclosure via [email protected]. We aim to acknowledge reports within 48 hours.

Cloud infrastructure controls

Hosted on modern cloud providers that maintain their own platform security certifications and operational controls.

What we do not claim

These are common procurement checklist items. We list them clearly so IT and compliance reviewers are not surprised later.

  • StockFlow SOC 2 Type II attestation (host infrastructure certifications ≠ product attestation)
  • FedRAMP, CMMC, ITAR, or equivalent government authorization
  • SAML / OIDC SSO (Azure AD, Okta, Google Workspace IdP federation)
  • Enforced multi-factor authentication (MFA / 2FA)
  • Customer-chosen data residency regions, on-prem, or air-gapped deploy
  • Classified-data or export-control workflows

Hosting providers may hold their own certifications. That is not the same as a StockFlow product attestation. For regulated defense or federal programs, confirm requirements independently before adopting.

Security roadmap

Priorities for organizations expanding into public service, security, and defense-adjacent logistics—without pretending they are already shipping.

  • SSO (SAML/OIDC) for enterprise identity providers
  • Enforced MFA for organization accounts
  • Richer customer-facing audit export for stock, assets, and permission changes
  • Clearer org-admin security controls (session policies, offboarding checklists)

Need SSO or MFA for a live tender? Contact us with your timeline—we use that signal to prioritize.

Report a vulnerability

If you believe you have found a security issue, email [email protected]. Full scope and process: Security Policy. Disclosure file: /.well-known/security.txt.

Trusted by small businesses

What our customers say

Super Kind! Quick replies from their support and very easy fixes, changed the dashboard a bit and customized it. Also gave me 450 items extra on the free plan just for me. Highly recommend and again great service!

Erasable Trading AU

Best customer service! Stockflow's customer support is fast and extremely helpful. They assisted me with customization of the software to improve my experience as a user.

Justin M.

Co-Owner, Consumer Goods

Frequently asked questions

Is StockFlow SOC 2, FedRAMP, CMMC, or ITAR certified?
StockFlow itself is not SOC 2, FedRAMP, CMMC, or ITAR certified. We host on cloud infrastructure that maintains industry-standard security certifications at the platform level. Organizations with those certification requirements should complete their own compliance review before adoption. See our defense and government pages for the same disclaimer.
Does StockFlow support SSO or MFA?
Not today. Authentication is email/password and Google sign-in, with invite-based teammate onboarding. Single Sign-On (SAML/OIDC via Azure AD, Okta, and similar IdPs) and enforced multi-factor authentication are on our roadmap for organizations that need corporate identity controls. Contact us if SSO/MFA is a procurement requirement so we can prioritize and discuss timing.
Where is StockFlow data hosted?
StockFlow Systems is a Belgium-based company. Application data is stored with our cloud database provider (Supabase) with encryption in transit (TLS) and at rest. We process personal data under the GDPR. Customer-chosen data residency regions, on-premises deployment, and air-gapped hosting are not available today see /gdpr for the full EU trust posture.
What access controls does StockFlow provide?
Warehouse owners can invite teammates and assign role presets (staff/admin) plus granular per-warehouse permissions for stock, products, exports, and team management. Stock movements and asset check-in/check-out are logged with user and timestamp. A customer-facing compliance audit console and SIEM export are not generally available yet.