Back to Pitchflo
P
PITCHFLO TRUST
Security Architecture & Compliance

Security & Trust Center

Pitchflo is engineered with defense-in-depth architecture to safeguard high-value client proposals, proprietary studio pricing, and legally-binding contracts.

1. Encryption & Data in Transit

All network communication between client browsers, living proposal portals, and Pitchflo servers is encrypted using modern Transport Layer Security (TLS 1.3).

HSTS Preload Protection

Forces strict HTTPS connectivity and shields against downgrade/man-in-the-middle attacks.

Strong CSP & Frame Ancestors

Prevents cross-site scripting (XSS), malicious script injections, and clickjacking.

2. Multi-Tenant Isolation & Authentication

Pitchflo enforces strict logical data boundary isolation:

  • Tenant Scoping: Every query, database access, and analytics ingestion is strictly scoped by user and workspace identifier.
  • Firebase & OAuth 2.0 Auth: Industry-standard authentication with hashed passwords, token revocation, and session verification.
  • Server-Side Authorization: Administrative endpoints (`/admin`) and mutation routes verify administrative role tokens server-side before execution.

3. Electronic Signature Audit Logs

When an enterprise client accepts an interactive proposal, Pitchflo records an immutable audit certificate containing:

✓ Signer Full Legal Name & Verified Email Address

✓ Timestamped Cryptographic Acceptance Code (UTC)

✓ Signer IP Address & Browser Fingerprint

✓ Exact Scope, Milestone & Pricing Tier Snapshot

4. Infrastructure & Vulnerability Management

Our infrastructure runs on SOC 2 Type II and ISO 27001 certified cloud environments (Google Cloud Platform, Cloudflare, Vercel). We enforce automated rate limiting on authentication and API routes to protect against brute-force attacks and abuse.

Responsible Disclosure

If you discover a security vulnerability, please report it immediately to our security team. We will acknowledge receipt within 24 hours.

security@pitchflo.online