Security at WebflowX
This page describes what is in place today and what is not. We would rather you know both before you buy. Last updated October 9, 2026.
What we do today
- Permissions on the server
- Roles and permissions are checked in the backend for every read and write, not just hidden in the interface. Four built-in roles plus custom roles built from 14 permissions.
- Two-step verification
- Anyone can add an authenticator app and keep backup codes. On Growth and Enterprise, owners and admins can require it for everyone in the workspace.
- Sign-in
- Email and password with emailed verification codes, plus Google and GitHub sign-in. Passwords are stored hashed.
- Webhook integrity
- Stripe and GitHub webhooks are verified by signature before anything is processed. Outgoing webhooks are signed so receivers can verify them.
- Abuse protection
- Rate limits and size limits guard notes, tasks, files, databases, comments, email, two-step codes and integrations. Uploads are checked against an allowed-type list and size caps.
- Audit log
- Admin actions are recorded in an audit log that owners and admins can review.
- Browser protections
- The site sends HSTS, a Content-Security-Policy, nosniff, a restrictive referrer policy and a tight Permissions-Policy, and limits framing.
- Your data
- Anyone can download their own data, and owners and admins can export the workspace. Guests only see the channels they are added to.
- Secrets
- Service keys are held in environment variables on the hosting platforms, not in the code.
What we do not offer yet
- SOC 2 or ISO 27001 certification. We have not been audited against either.
- A contractual uptime SLA, or a public status page with uptime history.
- SAML single sign-on and SCIM provisioning. Google and GitHub sign-in are available today.
- Choice of data region. Workspace data is stored in one US deployment (see Trust).
- Customer-managed encryption keys.
Service providers
The processors that handle data on our behalf are on the subprocessor list. Our Data Processing Agreement and SOC 2 roadmap are on the Trust page.
Report a vulnerability
Email hello@northfoundry.co with the details and steps to reproduce. Please do not access other people’s data or disrupt the service while testing. A machine-readable contact is published at /.well-known/security.txt.