Skip to content

Security Policy Base

OwnerFlowdence Security and Engineering
Applies to appAll Flowdence Marketplace cloud apps
Review cadenceQuarterly and after any significant security event
StatusBaseline policy
  • Source control with reviewed changes.
  • Release gates include lint/test/validation as defined per app.
  • Production claims must be traceable to implementation.
  • App permissions are scoped to minimum required capability.
  • Administrative operations require explicit authorization checks.
  • Secrets are not stored in source code.
  • Runtime secrets are stored in approved secure stores.
  • Secret rotation process exists and is documented per app.
  • Production logging avoids unnecessary sensitive data.
  • Monitoring and alerting are defined with responder ownership.
  • Security issues are triaged and remediated by severity.
  • Marketplace security requirement timelines are treated as release constraints.
  • Incident triage, escalation, and communication runbooks are maintained.
  • Post-incident review and corrective actions are tracked to closure.
  • Contact: security@flowdence.io
  • Report format: include impact, reproduction steps, and affected environments.