Security

Security is designed into the connection, the workspace and the output

PaddleFlo handles sensitive ServiceM8 access and customer records with clear boundaries and deliberately small, focused services.

Encrypted connection secrets

ServiceM8 access and refresh tokens are encrypted before they are stored.

Separated data services

Application state is stored in Cloudflare D1 and binary files and generated outputs are kept in R2.

Account and workspace boundaries

Authenticated actions check the signed-in user and their access to the selected workspace.

Verified billing events

Paddle handles payment details as merchant of record, while signed webhooks keep subscription state in sync.

Responsible reporting

If you believe you have found a security issue, do not include customer data or credentials in your first message. Email support@paddleflo.com with a concise description and a safe way for us to contact you.

This page describes current product controls and does not claim a third-party certification.

Ready when you are

A focused product is easier to understand and control.

Get your first month free and connect ServiceM8 when you are ready.

One month free Cancel before renewal