---
title: "ERP data security at 1flux"
description: "How 1flux handles ERP data security: database-level tenant isolation, roles and permissions, audit trails, signed file links and a backup before every release."
url: https://1flux.ai/security
last_updated: 2026-10-11
---

Security and trust

# ERP data security at 1flux

How 1flux keeps each customer's data separate, controls who sees what, records who did what, and protects your files and your numbers.

## In short

1flux protects ERP data with controls built into the product. Each customer's data is isolated inside the database with PostgreSQL row-level security. Access follows each person's role, reporting line and legal entities. Key records keep an audit trail, and all traffic uses HTTPS. Files use signed links that expire after 5 minutes, and every deployment takes a verified database backup first.

1. - HTTPS everywhere Traffic encrypted in transit
2. - Permissions and visibility Custom roles from 100+ permissions
3. - Row-level security Tenant isolation inside PostgreSQL
4. - Signed file links Download links expire after 5 minutes
5. - Verified backups Before every deployment

The layers that protect your data in 1flux, from HTTPS to a verified backup before every deployment.

At a glance

## What does 1flux do for ERP data security?

A quick read for IT reviewers: what 1flux does in each area.

| Area                    | What 1flux does                                                                                               |
| ----------------------- | ------------------------------------------------------------------------------------------------------------- |
| Customer data isolation | Isolated inside the database with PostgreSQL row-level security, failing closed                               |
| Access control          | Custom roles built from more than 100 permissions, reporting lines, record visibility and legal-entity access |
| Audit trails            | Activity on records, procurement documents, manual journals and workflow stages                               |
| Data in transit         | HTTPS everywhere, and TLS between the application and the database                                            |
| Files                   | Signed download links that expire after 5 minutes; uploads checked by file signature                          |
| Data integrity          | Edit-conflict protection, one posting gateway, closed periods and posted lines that can’t be changed          |
| Deployments             | A verified database backup before every deployment, and application rollback                                  |

Isolation

## How is each customer's data kept separate?

1flux isolates each customer’s data inside the database itself, with PostgreSQL [row-level security](https://1flux.ai/glossary/row-level-security), not only in application code.

- Each customer has a **workspace**: their organisation’s 1flux account.
- Row-level security policies on the database’s tenant tables only return rows that belong to the workspace making the request.
- If a request arrives without a workspace context, the database returns nothing. It **fails closed**.
- Isolation doesn’t depend only on every screen’s code applying the right filter.

Row-level security decides which rows a request can read, inside the database. No workspace context means no rows.

Access

## Who can see and change what?

1flux gives each person the access their job needs, through roles, reporting lines, legal entities and, where needed, individual fields.

- **Roles and permissions:** custom roles built from more than 100 permissions in 15 module groups. A non-admin can’t grant a permission they don’t hold, and role changes are audited.
- **Reporting hierarchy:** solid lines form the management tree; dotted lines add view-only or full access.
- **Record visibility:** choose whether everyone sees everything, or each person sees their own records and their team’s. New workspaces start Restricted.
- **Legal-entity access:** members can be limited to specific [legal entities](https://1flux.ai/platform/multi-entity), set when you invite them.
- **Field-level security:** hide a field or make it read-only, per role or person, on companies, contacts and items. It’s available, configured with our team.
- **Separate permission lanes:** in purchasing and receiving, requesters, approvers, buyers, storekeepers and invoice posters hold separate permissions. In accounting, preparing and posting journals are separate.
- **A price-free warehouse:** pick and dispatch screens never receive prices or credit terms from the server.
- **Leavers:** **Disable user** ends a person’s sessions immediately. **Reassign and deactivate** moves their companies, deals, tasks and direct reports to someone else in one step.
- **Invitations** expire after 7 days.

[Roles, permissions and audit](https://1flux.ai/platform/access-control)

Invite people by email with their roles and the legal entities they can access. Invitations expire after 7 days.

View as text

1. An admin opens Settings → Members & access and invites joel.fernandes\@sadaf.example by email.
2. They choose the Accountant role. Permissions from every selected role are combined.
3. Under Legal entity access they choose "Selected entities only" and tick Sadaf Building Supplies LLC (AE · AED), so Joel never sees the Saudi company.
4. The invitation waits in the Invitations list and expires on Oct 17, 2026, 7 days after it was sent.

Audit

## What does 1flux record about who did what?

1flux keeps an [audit trail](https://1flux.ai/glossary/audit-trail) where it matters most for a trading business:

- an **Activity** tab on companies, contacts, items and suppliers;
- a plain-sentence activity history on every procurement document;
- a per-entry audit trail on manual journals;
- stage history on deals, tasks and sales orders, including approvals, send-backs, overrides and automation runs.

Posted journal lines can’t be edited. A correction posts a reversal and a corrected entry, linked both ways.

1. Manual journal (Posted lines are locked): Reversed.
2. Reversal (Linked to the original): Posted.
3. Corrected entry (Linked both ways): Posted.

Posted lines never change. A correction posts a reversal and a corrected entry, linked both ways.

Transit and files

## How does 1flux protect data in transit and in files?

- **HTTPS everywhere.** Traffic between browsers and 1flux is encrypted with TLS, and so is the connection between the application and the database.
- **Files** are kept in S3-compatible object storage. Downloads use signed links that expire after 5 minutes. Uploads are checked against their file signature, so a file can’t pass itself off as a different type.
- **Customer quotation links** can have a password and an expiry of 1–365 days, and you can revoke them at any time.
- **Approved quotations are locked.** On approval, the PDF and its data are frozen. The same file is emailed, shown on the customer link and downloaded, and it can’t be altered.

1. Upload (Checked by file signature).
2. Object storage (S3-compatible).
3. Signed link (Expires after 5 minutes).
4. Download (Over HTTPS).

Uploads are checked by file signature, and every download uses a signed link that expires after 5 minutes.

Integrity

## How does 1flux protect the integrity of your numbers?

- **No silent overwrites.** If two people edit the same record, the second save is refused with a “refresh and try again” message.
- **One posting gateway.** Every journal and stock movement is written through one posting service. It checks that the period is open, the entry balances and the accounts are mapped, and a repeated submit can’t post twice.
- **Closed periods refuse every posting.**
- **Posted entries stay posted.** Corrections leave a visible trail.

[Automated posting in 1flux](https://1flux.ai/products/accounting/automated-posting)

Every posting passes the same gateway. If a check fails, nothing posts and the message says why.

Deployments

## How are deployments and backups handled?

- **Every deployment takes a verified database backup first.**
- **The application can be rolled back** to the previous release.
- **Database changes are versioned migrations**, with integrity checks on every deployment.
- **Hosting:** 1flux runs in containers served over HTTPS, on DigitalOcean with a managed PostgreSQL database.

1. Verified backup (Before every deployment).
2. Migrations (Versioned and checked).
3. New release (Served over HTTPS).
4. Rollback (To the previous release).

Every deployment starts with a verified database backup, and the application can roll back to the previous release.

AI

## How does 1flux handle data in AI features?

**Import PO with AI**, in the quotation builder, turns a customer’s PO or RFQ into a draft quotation. It only processes the file you choose to upload.

- You upload a customer’s PO or RFQ (PDF, PNG, JPEG or WebP, up to 10 MB).
- 1flux sends that file, with fixed extraction instructions, to a large language model through a model gateway. Matching to your catalogue happens inside 1flux afterwards.
- The model works to a strict schema. It never invents values: anything missing is left blank.
- It ignores instructions embedded in the uploaded document.
- The source file is attached to the quotation with an “AI source” badge. It’s visible to the customer by default, and you can change that on the quotation.

[AI in 1flux](https://1flux.ai/platform/ai)

1. Your file (Up to 10 MB).
2. Model gateway (Fixed instructions).
3. Strict schema (Nothing invented).
4. Matched in 1flux (Item codes to your catalogue).
5. Draft quotation (Source file attached).

Only the file you upload goes to the model. Matching to your catalogue happens inside 1flux.

Security research

## Responsible disclosure

If you believe you've found a security vulnerability in 1flux, please tell us.

How to report

[1flux.ai/contact · Security or a questionnaire](https://1flux.ai/contact)

Choose **Security or a questionnaire** as the topic. Please don't report vulnerabilities through social media.

**Please include** the affected page or feature, the steps to reproduce the issue, its impact, and how to contact you.

**While testing, please:**

- only use accounts and workspaces you own or have permission to test;
- not access, change or delete other customers’ data;
- not run denial-of-service, spam or social-engineering tests;
- give us reasonable time to fix the issue before you disclose it.

**What we’ll do:** acknowledge your report, keep you updated, and credit you if you’d like.

FAQ

## Questions, answered

Still deciding? [Talk to sales](https://1flux.ai/contact)

### How does 1flux keep each customer's data separate?

1flux isolates each customer's data inside the database with PostgreSQL row-level security, not only in application code. Row-level security policies on the tenant tables return only the rows that belong to the workspace making the request. If a request arrives without a workspace context, the database returns nothing, so isolation fails closed.

### How do people sign in to 1flux?

1flux sign-in uses an email and password, or a Google account. Admins invite colleagues by email, and invitations expire after 7 days. Access then follows each person's role, reporting line and legal entities, a non-admin can't grant a permission they don't hold, and **Disable user** ends a person's sessions immediately.

### What happens to a leaver's access in 1flux?

1flux ends a leaver's access in one step. **Disable user** ends their sessions immediately, and **Reassign and deactivate** moves their companies, deals and tasks, and their direct reports, to someone else. Nothing is left without an owner, and nobody keeps access they no longer need.

### Does 1flux keep an audit trail?

Yes. 1flux keeps an Activity tab on companies, contacts, items and suppliers, a plain-sentence activity history on every procurement document, a per-entry audit trail on manual journals, and stage history on deals, tasks and sales orders, including approvals, send-backs and overrides. Posted journal lines can't be edited: a correction posts a reversal and a corrected entry, linked both ways.

### Is our data encrypted in transit?

Yes. Browsers connect to 1flux over HTTPS, and the application connects to its database over TLS. File downloads use signed links that expire after 5 minutes, and uploads are checked against their file signature, so a file can't pass itself off as a different type. Customer quotation links can carry a password and an expiry.

### How does 1flux handle data sent to AI?

1flux sends only the file you choose to upload in Import PO with AI, with fixed extraction instructions, to a large language model through a model gateway. Matching to your catalogue happens inside 1flux afterwards. The model works to a strict schema, never invents values and ignores instructions embedded in the document, and the source file is attached to the quotation.

### Can we export our data?

Yes. 1flux exports your data area by area: companies and contacts to CSV or Excel, items to Excel, and ledgers, the chart of accounts, receivables, customer statements, stock movements, valuation and the purchase order report to CSV. CSV files open correctly in Excel, including Arabic text, and quotations download as PDFs.

Related

## Keep exploring

### [Roles, permissions and audit](https://1flux.ai/platform/access-control)

Custom roles, record visibility along reporting lines, entity access and row-level security.

### [AI in 1flux](https://1flux.ai/platform/ai)

AI that works on the same records, permissions and audit trail as your team, and drafts quotations from customer POs today.

### [Multi-company and multi-entity](https://1flux.ai/platform/multi-entity)

Several legal entities in one workspace, each with its own registrations, currency and books.

### [Automated posting](https://1flux.ai/products/accounting/automated-posting)

Receipts, deliveries, invoices and payments post balanced journals through one gateway.

### [Contact](https://1flux.ai/contact)

Sales, support, partnerships, press and security: choose the right contact.

### [Pricing](https://1flux.ai/pricing)

How a 1flux price is put together, and how to get a written proposal.

Last updated 11 October 2026
