How PowderFlow is built, hosted, and accessed — described as it is, not as we would like it to be.
PowderFlow runs in the United States. The application and its API are hosted on Railway; the marketing site and front end are served by Vercel. Your shop's records are stored in a PostgreSQL database hosted by Neon, and files you upload — job photographs, packing slips, documents — are stored in Cloudflare R2.
Production, staging, and development run against separate databases. Every subprocessor that can see customer data is listed on our subprocessors page.
In transit: every connection to PowderFlow is served over HTTPS. The application sends an HTTP Strict-Transport-Security header with a one-year max-age, applied to subdomains, so a browser that has visited once will refuse to connect over plain HTTP. The application also sends a Content-Security-Policy.
At rest: your data is encrypted at rest by the platforms that store it — Neon for the database and Cloudflare R2 for uploaded files. We state this as a property of those providers, because that is what it is: we rely on their encryption rather than implementing our own on top of it.
PowderFlow is multi-tenant: every shop's records carry an organization identifier, and requests are scoped to the organization of the signed-in user. Files in storage are addressed by keys that carry the owning organization, and a request for a file that cannot be attributed to your organization is refused rather than served.
PowderFlow staff do not browse customer shops as a matter of course. Entering your shop requires an access grant recorded in the database, and the grant is checked on the request path — it is not an honour system. Every grant has an expiry after which it stops working, and the owner can revoke it at any time from the application.
One exception, stated plainly because a security page that hides it is not one: PowderFlow staff can create a break-glass grant for themselves, without the owner clicking first, for urgent support situations. A break-glass grant is stored as such and is distinguishable from an owner-consented one, so it appears in the access history rather than looking like something you approved.
Sign-in, sessions, and account management are handled by Clerk. PowderFlow does not store your password. Permissions inside a shop are role-based, so an employee sees less than a manager and a manager sees less than the owner.
PowderFlow does not hold a SOC 2 report, an ISO 27001 certificate, or any other third-party security audit. We are a small company and we would rather tell you that than imply otherwise.
We do not offer a signed Data Processing Agreement yet. If your procurement process requires one, email us and we will tell you where that stands.
If you believe you have found a security problem in PowderFlow, email support@powderflowsystems.com with the details. Please give us a reasonable chance to fix it before disclosing it publicly. We will confirm we have received your report.
See also our subprocessors and privacy policy.