Security · Reversibility · Commitments

A platform you can audit.

Entrusting your flows and your data to a platform is a commitment measured in years. This page answers the questions a decision-maker has to ask beforehand: how the platform is secured, how your data stays yours, and how you leave the day you decide to.

Start with a pilot Ask your questions

Security as standard

The protections ship with the platform — never as an option, never as an extra line on the quote.

Isolation per organisation

Each organisation has its own space: users, applications, data, documents and messaging are isolated from one another.

Least privilege

Granular roles and rights; programmatic access goes through personal tokens with restricted scopes, revocable at any time.

Watched sign-ins

Progressive throttling of sign-in attempts, access history with device and region, network access rules specific to each organisation.

Controlled documents

Antivirus scanning on every document upload; document spaces are closed by default, opening one is an explicit decision.

Encrypted exchanges

Access to the platform and to the APIs runs over TLS; integration secrets live in a dedicated vault, never inside the flows.

Regular audits

The platform is audited regularly, and every finding is tracked through to its fix. Being open about that is part of the product.

Your data and your applications stay yours

Reversibility is not a contract clause here, it is a property of the architecture.

Open standards

REST, OData, OpenAPI, SQL, WebDAV, IMAP/SMTP, S3-compatible storage: no proprietary format stands between you and your data.

Exportable applications

Your applications are versioned models: each exports as a re-importable package — for archiving, review or migration.

Your infrastructure

The platform installs on your infrastructure, in a private cloud or in a hybrid setup. Where your data lives is your decision.

No lock-in by design

Nothing you build here needs Clomoon to be read: the flows, the models and the documents leave in open formats.

What we commit to

A named contact

An engineer who knows your setup, not a ticket queue. Escalation paths are written down before you need them.

Traceable fixes

Every reported defect gets a reference, a diagnosis and a fix you can verify on your own instance.

Documented upgrades

What changes, what breaks, what you have to do: stated before the upgrade, not discovered after it.