Security and data privacy are fundamental priorities within Zoho Flow. As a platform that connects applications and transfers data between systems, Zoho Flow is built with robust safeguards to ensure that your information remains protected at every stage of an automated workflow. This article outlines the key security and privacy features of Zoho Flow and what they mean for your organisation.
All data transmitted through Zoho Flow is encrypted in transit using TLS (Transport Layer Security). This applies to data moving between your connected applications and Zoho Flow's servers, as well as to communication between Zoho Flow and any webhook endpoints. Data stored within Zoho Flow, including connection credentials and flow execution logs, is encrypted at rest.
When you authenticate a connected application within Zoho Flow, your credentials (such as OAuth tokens, API keys, or access tokens) are stored in an encrypted format. Zoho Flow does not store or expose your passwords. For OAuth-based connections, access tokens are used in place of your actual login credentials, and these tokens can be revoked at any time from within the connected application's settings.
Zoho Flow provides role-based access controls that allow administrators to manage who within an organisation can create, edit, view, or delete flows and connections. This ensures that sensitive integrations and data pipelines are only accessible to authorised team members. Connections created by one user can be restricted so that other users cannot view the underlying credentials, even if they use the same connection in a flow.
Connections in Zoho Flow can be designated as private (accessible only to the creator) or shared (accessible to other users in the organisation). When sharing a connection, the credentials remain hidden; other users can use the connection in their flows without being able to see the underlying authentication details.
Zoho Flow maintains a detailed history of every flow execution, including the time it ran, which steps were executed, the data processed at each step, and whether the run succeeded or failed. This audit trail supports accountability and makes it straightforward to investigate any unexpected behaviour or data discrepancies. Access to execution history can be controlled through user permissions.
Zoho Flow is designed to support compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. Zoho, as the data processor, operates data centres across multiple regions, including Europe, allowing organisations to choose where their data is stored. Zoho's Data Processing Addendum (DPA) is available for customers who require it for compliance purposes, and Zoho regularly undergoes independent security audits and certifications.
Zoho offers data residency options that allow organisations to specify which geographic region their data is stored in. For UK and EU-based customers concerned about data sovereignty, selecting a European data centre ensures that data processed through Zoho Flow does not leave the region. This is particularly relevant for organisations subject to GDPR or sector-specific regulations.
Zoho maintains a range of security certifications and independently verified compliance standards, including ISO 27001 (information security management) and SOC 2 Type II. These certifications demonstrate a commitment to maintaining rigorous information security controls across the organisation's infrastructure and processes.