Security
Last updated 5 October 2026
Gridfloo holds a company’s work: its cards, flows, files, chat and, when connected, its mail and calendars. This page says plainly how we protect that, what we have tested, and what is not there yet. Questions go to security@gridfloo.com.
Your data stays yours, and separate
- Access is enforced in the database itself, not only in the app. Every request is answered with the rights of the person asking, so a mistake on one screen cannot show one company’s data to another.
- Changes to these rules are proved, not assumed. Before a change to who-sees-what goes live, we record what every user can see and compare it after the change; it ships only with zero differences.
- Files follow the same rules. A file is handed out through a short-lived signed link, issued after the same permission check as the item it belongs to — or through a share link that someone with access deliberately created.
- Access tokens for connected mailboxes and calendars are kept on the server and never sent to the browser.
You can take everything with you
- Workspace export: an owner or admin can download a full copy of the workspace at any time — every record, every file and earlier versions, chat files, receipts and the member list — in open formats (JSON, CSV and the original files) that need nothing from Gridfloo to read. Passwords and sign-in keys are never included.
- Your own copy, in your own storage: Gridfloo can send that full copy every day or every week to a bucket your company owns (Amazon S3, Cloudflare R2 or any S3-compatible storage), so you always hold a current copy, whatever happens to Gridfloo. Gridfloo only needs permission to write there; your bucket’s own rules decide how long copies are kept, and a failed copy alerts your workspace admins.
Signing in
- People sign in with their Microsoft or Google work account, so your own IT’s rules apply: two-factor authentication, conditional access, and switching an account off when someone leaves.
- Sign-in by e-mail code is available for people without either, with optional two-step sign-in: after the e-mail code, a code from an authenticator app (with one-time recovery codes as a fallback). Each code works once, and five wrong ones lock it for 15 minutes. A workspace can require it.
- Your rules for your workspace: its admins choose which ways of signing in it accepts, and can require your company’s own accounts (your Microsoft work tenant or Google Workspace domain). This is enforced by the database itself: work in a workspace stays closed to anyone who signed in another way.
- Verified company domains: a workspace proves it owns its e-mail domain with a DNS record, which is checked again every day. A domain can be verified by one workspace only.
- Joining with a company address, if the workspace allows it: people whose sign-in proves an address at a verified domain (a Microsoft work account, a Google Workspace account of that domain, or a code sent to the address) can join directly, or ask and wait for an admin to approve. Someone who was removed can never let themselves back in.
Encryption
- All traffic is encrypted (HTTPS/TLS).
- Data is encrypted at rest with our hosting providers.
- Backups are encrypted before they leave, with a key only Gridfloo holds, offline. The provider that stores them cannot read them.
Backups, and proof they work
- Every night, the whole database and every file are copied off-site, to a different provider and region than the live system (Amazon Web Services, Singapore).
- Copies are kept for 180 days. For the first 30 days they are locked: nobody can delete or change them, Gridfloo included.
- A failed or late backup alerts us immediately, and our backup dashboard flags a copy that is much smaller than the night before.
- Restores are tested every quarter. The last test, on 4 October 2026, restored the full database with no errors: every table, rule and row accounted for.
- On top of this, the database provider keeps its own daily backups.
A record of who did what
- Audit log: workspace admins see who did what — sign-ins (including failed ones and ones refused by the workspace’s sign-in rule, with country), members and roles, invitations, sharing and public links, files deleted, exports and their downloads, backups to your own storage, settings and billing.
- Filter it by kind, person and date, and download it as a spreadsheet (CSV).
- Entries cannot be changed or deleted by anyone, Gridfloo included; the database refuses it. The log is part of the workspace export, and it outlives a deleted workspace.
How we run Gridfloo
- Our administrator accounts for code, hosting, database, file storage, backups, payments and company e-mail all use two-factor authentication.
- Every change to the code is scanned for accidentally included passwords or keys.
- Backup credentials can only write new copies; they cannot read or delete existing ones.
- No one at Gridfloo reads your content unless you ask us to (for support), it is needed for security, or the law requires it.
Where data is kept
- Database: Japan (Tokyo). Files: Cloudflare, Asia-Pacific. Encrypted backups: Singapore.
- The full list of providers, and what each one does, is in the privacy statement (section 6).
AI
- Your content is never used to train AI models.
- Workspace admins choose which AI providers may be used for their workspace. Only the content needed for the feature someone uses is sent.
Privacy and GDPR
- Gridfloo is provided by Leworks International AB, Stockholm, Sweden, and works under the GDPR.
- For a company’s workspace, the company decides about the data and we process it on its behalf. A data processing agreement is available on request.
- See the privacy statement for what is stored, why, and your rights.
On request and planned
These are not available yet. If your organisation needs one of them, tell us: it decides what we build next.
| What | Status |
|---|---|
| Files in your own storage: your workspace’s files kept in your own S3-compatible bucket | On request |
| EU data centre: database and files kept in the EU | Planned |
| Single sign-on (SAML) and user provisioning (SCIM) | On request. Domain verification, which it builds on, is in place. |
| Independent penetration test | Planned |
| ISO 27001 certification | Not yet. We will say so here when it is under way. |
Reporting a vulnerability
If you believe you have found a security problem, write to security@gridfloo.com. We answer quickly, keep you informed while we fix it, and will not take action against good-faith research that avoids other people’s data.