Security at WebflowX

This page describes what is in place today and what is not. We would rather you know both before you buy. Last updated October 9, 2026.

What we do today

Permissions on the server
Roles and permissions are checked in the backend for every read and write, not just hidden in the interface. Four built-in roles plus custom roles built from 14 permissions.
Two-step verification
Anyone can add an authenticator app and keep backup codes. On Growth and Enterprise, owners and admins can require it for everyone in the workspace.
Sign-in
Email and password with emailed verification codes, plus Google and GitHub sign-in. Passwords are stored hashed.
Webhook integrity
Stripe and GitHub webhooks are verified by signature before anything is processed. Outgoing webhooks are signed so receivers can verify them.
Abuse protection
Rate limits and size limits guard notes, tasks, files, databases, comments, email, two-step codes and integrations. Uploads are checked against an allowed-type list and size caps.
Audit log
Admin actions are recorded in an audit log that owners and admins can review.
Browser protections
The site sends HSTS, a Content-Security-Policy, nosniff, a restrictive referrer policy and a tight Permissions-Policy, and limits framing.
Your data
Anyone can download their own data, and owners and admins can export the workspace. Guests only see the channels they are added to.
Secrets
Service keys are held in environment variables on the hosting platforms, not in the code.

What we do not offer yet

Service providers

The processors that handle data on our behalf are on the subprocessor list. Our Data Processing Agreement and SOC 2 roadmap are on the Trust page.

Report a vulnerability

Email hello@northfoundry.co with the details and steps to reproduce. Please do not access other people’s data or disrupt the service while testing. A machine-readable contact is published at /.well-known/security.txt.