Local workflow input
Client-sidePasted or uploaded workflows can be analysed locally. Connected-platform retrieval and other optional actions use separate requests.
Core workflow analysis follows a simple boundary: parsing and analysis run in your browser; optional account, AI, background-migration, and target-push features use separate server or provider requests.This page explains the main data paths. For details, see the Data Processing Agreement.
Pasted or uploaded workflows can be analysed locally. Connected-platform retrieval and other optional actions use separate requests.
Core parsing, data-flow analysis, security checks, diagrams, and supported workflow conversions run in your browser.
Markdown, DOCX, PDF, PNG, standalone HTML, and JSON outputs are generated in the browser.
Portfolio entries, document-version history, and manually imported blueprints can be saved in browser local storage.
Supabase stores account, plan, and usage records. Connected platform credentials saved for account features are encrypted at rest and decrypted server-side when used.
AI features send the requested prompt or workflow context from a server route to the custom endpoint configured in account settings. Provider terms apply.
After the consent disclosure and a separate action, a signed-in Pro user can send a workflow for server-side conversion. Job payloads are AES-256-GCM encrypted in Redis, removed at terminal updates, and have a 24-hour TTL backstop.
A signed-in Pro user can push to a connected Make.com or n8n account after the consent disclosure. The server uses the encrypted-vault credential to create an inactive workflow for review.
Core local path
Optional server/provider paths
Stored in this browser
Core workflow analysis and supported conversions run in the browser. Optional server and AI-provider features are described above.
Connected platform credentials and background migration payloads are encrypted at rest. This is not a certification or a claim that every stored record is encrypted.
The public Data Processing Agreement describes the terms for data processed by Xray Flow.
View DPA →Open DevTools → Network. Filter by the Fetch/XHR type. Trigger an analysis. You'll see only the initial blueprint fetch (if using API key) — no analysis payloads.
The Rust analysis engine is open source. Compile it yourself and verify the WASM binary matches what loads in your browser.
Export a report as Markdown. The file contains exactly what was generated client-side — no hidden server-side additions.