CredentialFlow sits where credentials move from issuer to recipient: the moment before SSO, MFA, and device trust take over. Split-trust encryption by default. Zero-knowledge mode available. Every delivery produces tamper-evident proof.
We observe the credential lifecycle only as far as delivery and verification require. We don't watch what happens after.
CredentialFlow exists for the bootstrap boundary before durable trust is established.
First-access trust establishment with session-level evidence. One architecture covers credential delivery to new hires and Help Desk verification before sensitive actions. Each retrieval is recorded with the session context it occurred in: who was verified, what was delivered, and the network context of the handoff.
Security is our baseline, not a premium feature. Split-trust encryption, zero-knowledge mode, and tenant-level isolation aren't features we added later. They're the foundation. Every organization receives maximum-strength encryption and the same protective controls, regardless of plan.
Built for regulated industries. Available to everyone.
View 3rd Party Trust CenterCovers logical access, transmission security, system monitoring, risk management, and availability. Full control mapping available under NDA.
Automatic data minimization and configurable retention policies to safeguard personal info.
Certification targeted for 2026. Controls already aligned today.
Technical controls aligned with HIPAA requirements. BAA on roadmap.
All customer data is currently hosted and processed within the United States. We are actively planning expansion to additional global regions to support our international customers' compliance needs.
AWS WAF and an Application Load Balancer sit at the edge, every connection uses TLS 1.3, and multi-layer rate limiting blunts brute force and enumeration. None of that is what protects your credentials. An attacker who gets past all of it reaches ciphertext and at most one of two key shares. The other is held by an independent custodian, and neither decrypts alone.
We deliver notifications, not secrets. Messaging providers receive routing metadata only. Secret stays encrypted in our environment until single-use retrieval.
CredentialFlow is built on enterprise infrastructure. None of it can read a credential.
| Provider | Role | Can it see the credential? |
|---|---|---|
| Amazon Web Services | Hosting, infrastructure, database | No. Stores ciphertext only. Key shares are split across independent custodians, so no single party can decrypt. |
| WorkOS | Dashboard authentication, SSO, MFA | No. Handles sign-in to CredentialFlow itself. Never touches delivered credentials. |
| Twilio | SMS notification delivery | No. Receives routing metadata only, never credential content. |
| SendGrid | Email notification delivery | No. Receives routing metadata only, never credential content. |
| Stripe | Billing and subscription payments | No. Handles card data directly and sits outside the delivery path entirely. |
Authentication is handled entirely by WorkOS. CredentialFlow does not collect, store, or have access to your dashboard password. The current subprocessor list is maintained in our Privacy Policy.
Isolation, layered encryption, and zero-knowledge options work together so one organization's risk never becomes another's.
Each organization has unique encryption keys and a cryptographically enforced database boundary. Row-Level Security at the PostgreSQL layer ensures no application-layer bypass can expose another tenant's data.
Key shares are split between an independent vault and CredentialFlow's infrastructure. Combined only in temporary memory during use.
Client-side encryption keeps even CredentialFlow blind to the secret when compliance demands it.
Every API request passes through an independent authentication chain covering identity verification, tenant resolution, role enforcement, and resource ownership, evaluated sequentially. A bypass at any single layer cannot cross tenant boundaries.
Cryptographically signed, tamper-evident logs capture the who/what/when for each handoff, visible only to your org.
Delivery tokens are stored only as a cryptographic one-way hash. CredentialFlow cannot retrieve the original value. Multiple failed retrieval attempts trigger automatic purge before the credential can be extracted. Unclaimed secrets expire within 24 hours. Nothing lingers.
CredentialFlow offers three encryption modes:
Split-trust dual control is the foundation. BYOK uses your KMS key as one of the two shares. Zero-knowledge layers client-side encryption above the stack.
All three modes are included in every plan, and the layers compose: BYOK and zero-knowledge build on top of dual control, not around it.
Stack split-trust dual control with BYOK key sovereignty and zero-knowledge browser encryption for your strongest possible protection profile.
Separation of duties enforced at the data layer: each team operates with precisely scoped visibility.
Manage the onboarding pipeline and confirm delivery, without ever touching a credential value.
Can access
Cannot access
Provision and manage credentials while remaining blind to employee personal information.
Can access
Cannot access
Control security posture and review the complete audit trail. Credential content stays protected at the encryption layer.
Can access
Every credential lifecycle event is tracked, signed, and surfaced so your security team always has evidence, not assumptions.
From compliance teams and security reviewers. Can't find what you need? Contact us
Split-trust encryption, tamper-evident audit chains, and zero plaintext storage. Live in your environment in under five minutes.