In beta with first customers. Out of beta and taking new customers from 26 October. Talk to us

Security

Isolated per customer, closed to the internet.

StencilFlow runs as a dedicated deployment per customer: its own servers for the application and the StencilFlow agent, its own database and its own configuration. Access goes through a zero-trust layer, so there are no inbound ports to attack.

Architecture

Six principles, built into every deployment

Dedicated deployment

Separate servers for the application and the StencilFlow agent, and a separate database, for every customer. No shared tenancy, no data mixing.

No inbound ports

Access through a zero-trust gateway with single sign-on. The server itself is not reachable from the internet.

Your keys, your AI

AI features run on your own model provider keys. Connector secrets are encrypted at rest.

Role-based access

Access per department, process and workflow, at design time and at runtime.

Every action recorded

Versions, runs, reviews and approvals are logged with who did what and when.

Human activation

Nothing goes live without a signed-in person. Agent identities cannot activate workflows.

Operations

Hosting & data agreements

Hosting
Hosted in the EU (Amsterdam)
Data agreements
We follow the NLdigital Data Pro Code.

AI boundaries

Design time is AI. Runtime is not.

AI makes workflows faster to build. It does not make decisions in production on its own.

  • AI assists design and reading

    Assistants help draft workflows and mappings, and can read scans and unfamiliar layouts.

  • Runtime is deterministic rules

    What runs in production is a fixed graph of steps and rules you approved, with a recorded reason for every outcome.

  • Your own model provider keys

    AI features use model provider keys you supply, so your data stays within agreements you control.

  • Assistants draft and test, never activate

    An assistant can propose and test a workflow. Only a signed-in person can activate it.

  • Credentials stay out of reach

    Connector secrets are never passed to assistants. They are encrypted at rest and used only by the runtime.

The StencilFlow agent

The agent works in a sealed sandbox

When the StencilFlow agent builds or tests a workflow, it works in its own isolated sandbox, created per session, on a server separate from the application. The sandbox has no internet access and can reach exactly two things, both through a StencilFlow gateway that checks every call.

Agent sandbox

One per session · no internet

Gateway
  • AI inference provider

    For the model itself, using your provider keys.

  • StencilFlow tools

    The StencilFlow MCP endpoints, with the same role-based access as the person working with the agent.

No route to the internet or your network

No internet access

The sandbox runs on a network without outbound access. It cannot download, browse or send data anywhere else.

Only pre-installed, verified software

Tools come from a fixed, reviewed image built by StencilFlow. Nothing new can be installed during a session.

Isolated per session

Each session gets its own sandbox with a kernel-level isolation layer, a read-only system, no extra privileges and fixed memory and process limits.

No credentials inside

The sandbox holds only a short-lived token for the current turn. Provider keys and connector secrets stay on the gateway.

Sensitive actions need a person

Creating connectors or API actions asks for confirmation, and only a signed-in person can activate a workflow.

Governance

One managed platform, not a patchwork of private AI tools

Teams want to automate their own work, and AI makes that tempting to do on the side: a personal chatbot account, a script, a browser extension. Each one is quick to start, and together they become a risk nobody can see. StencilFlow gives teams the same speed to build their own automations, inside one platform that IT can oversee.

  • Overview

    Built on the side: Automations live in personal accounts, scripts and spreadsheets that nobody else can see.

    Built in StencilFlow: Every workflow, version and run in one place, organised by department and process.

  • Data

    Built on the side: Business documents pasted into tools outside your agreements.

    Built in StencilFlow: Data stays in your dedicated deployment, and AI runs only on your own provider keys.

  • Outcomes

    Built on the side: A prompt that may answer differently each time, with no record of why.

    Built in StencilFlow: Deterministic rules in production, with a recorded reason for every outcome.

  • Credentials

    Built on the side: System passwords and API keys spread across private tools.

    Built in StencilFlow: Connector secrets encrypted and managed centrally, with role-based access.

  • Changes

    Built on the side: A change goes live the moment someone saves it.

    Built in StencilFlow: A person reviews and activates every change, and every version is kept.

  • Continuity

    Built on the side: When the builder leaves, the knowledge leaves too.

    Built in StencilFlow: Workflows are readable configuration, and the StencilFlow agent can explain them to the next person.

Due diligence

Documents for your security review

We share these with your security, privacy or procurement team as part of a pilot.

Request the security pack
  • Security & data-flow one-pagerAvailable on request
  • Data processing agreement (DPA)Available on request
  • Subprocessor listAvailable on request

Ready to look at your inbox?

Bring one process and a handful of real documents. We show you the path from inbox to decision, on your own data.