XFXray Flow

Security at XrayFlow

Trust is our product. Here is exactly how we handle your data.

1. The "Ephemeral" Promise

XrayFlow is designed as a Client-Side Proxy.

  • No Storage: Your Make.com API Key is never written to a database. It is stored in your browser's encrypted session memory and sent to our server only for the duration of the request.
  • Volatile Memory: Once your report is generated, the key is flushed from our server's RAM.

2. Infrastructure

  • Hosting: We are hosted on Vercel (Australia), utilizing their secure, ISO-certified serverless infrastructure.
  • Encryption: All data in transit is encrypted via TLS 1.3 (Bank-Grade Encryption).
  • WAF: We are protected by Cloudflare Enterprise-grade DDoS protection.

4. Live Blueprint Analysis

See our engines analyze your actual workflow in real time.

Paste a blueprint or load a scenario to run Xray Flow's full engine suite: security & resilience scoring, data flow & PII mapping, compliance checks (GDPR/CCPA), and module configuration extraction.

Two processing modes:

  • Local blueprint analysis: If you paste or upload a blueprint, analysis runs entirely in your browser via our Rust WASM engine. No data leaves your browser.
  • Connected Make retrieval: When you connect your Make.com account or provide an API key, the key is transmitted over TLS to retrieve the selected scenario and is not persistently stored.
Run Live Analysis

5. Data Privacy

  • Your Intellectual Property: We do not claim ownership of your blueprints.
  • No Training: We do not use your blueprints to train AI models.

6. Security Architecture & Data Flow

XrayFlow implements a privacy-by-design architecture with two distinct processing modes. The diagrams below illustrate how data flows through each mode and the security controls at each layer.

Mode 1: Local Blueprint Analysis

Paste or upload a blueprint — zero server interaction

1. Blueprint Input

User pastes JSON or uploads .json file in browser

2. Client-Side Parsing

Rust WASM engine parses blueprint in browser memory

3. Analysis Engines Run

Security, data flow, compliance, module extraction — all local

4. Report Generated

Diagram, documentation, audit findings created in browser

5. User Exports/Downloads

PDF, DOCX, Markdown downloaded directly — no server upload

Security Properties: Zero network requests for analysis · Blueprint never leaves browser · No server-side processing · No persistent storage

Mode 2: Connected Make.com Retrieval

Connect Make.com account — ephemeral server-side fetch

1. API Key Entry

User provides Make.com API key (stored in browser encrypted session)

2. Scenario Selection

User selects scenario from their Make.com account via UI

3. Ephemeral Server Fetch

API key sent over TLS to server → fetches scenario → key flushed from RAM

4. Client-Side Analysis

Blueprint sent to browser → WASM engines run locally (same as Mode 1)

5. Report Generated & Exported

Results created in browser, downloaded directly

Security Properties: API key never persisted to database · TLS 1.3 for all transit · Server RAM flushed post-request · Analysis still runs client-side · Blueprint not stored server-side

Data Protection

  • TLS 1.3 for all transit
  • Web Crypto API for client encryption
  • No blueprint persistence
  • API keys: encrypted session storage

Infrastructure

  • Vercel (Australia) — ISO 27001, SOC 2
  • Cloudflare Enterprise WAF & DDoS
  • Serverless — no persistent servers
  • CSP, HSTS, COOP, CORP, COEP headers

Data Retention & Access

  • Account data: 90 days post-deletion
  • Billing: 7 years (tax law)
  • Analytics: 13 months (opt-in)
  • Blueprints: never stored

7. AI Data Processing & Provider Disclosures

XrayFlow offers optional AI-powered insights (architecture review, improvement suggestions) as a Pro feature. When enabled, the following applies:

What Data Is Sent to AI Providers

  • Blueprint structure (module types, connections, names)
  • Security findings summary (no raw secrets)
  • Module configuration parameters (sanitised)
  • Raw API keys, credentials, or PII — never sent

Provider & Model

  • Provider: Google (Gemini) via Vertex AI
  • Model: Gemini 1.5 Pro / Flash
  • Region: Australia (Sydney) / US (configurable)

Data Retention & Training

  • Google does not use your data to train models (Vertex AI data governance)
  • Prompts & responses logged for 30 days for abuse monitoring only
  • No XrayFlow staff access to AI conversation logs

User Controls

  • AI insights are opt-in (Pro only, disabled by default)
  • Can be disabled anytime in Settings → AI Settings
  • Per-analysis toggle: run with or without AI

Frequently asked questions

Where is my Make.com API key stored?

Your API key is never written to a database. When you connect your Make.com account, the key is stored in your browser's encrypted session memory and sent to our server only for the duration of the request to retrieve your scenario, then flushed from RAM. For local blueprint analysis (pasted JSON), no API key is needed and no data leaves your browser.

Do you store my blueprints or scenarios?

No. Blueprint processing is ephemeral — we do not retain your scenarios after your report is generated. For local analysis, the blueprint never leaves your browser. For connected Make retrieval, the blueprint is fetched, processed in-memory, and discarded.

Do you use my data to train AI models?

No. We do not use your blueprints to train AI models. AI insights (where enabled) are generated via third-party providers with their own data retention policies — see our Privacy Policy for details.

How is my data encrypted?

All data in transit is encrypted with TLS 1.3. We are hosted on Vercel (Australia) with Cloudflare Enterprise DDoS protection. Local browser analysis uses Web Crypto API for any client-side encryption operations.

Is Xray Flow affiliated with Make.com?

No. Xray Flow is an independent tool and is not affiliated with Make.com.

8. Incident Response & Vulnerability Reporting

We take security incidents seriously and have established processes for detection, response, and responsible disclosure.

Incident Response

  • 24/7 monitoring via Vercel & Cloudflare alerts
  • Incident classification: SEV-1 (critical) to SEV-4 (low)
  • SEV-1 response: <15 min acknowledgement, <1 hr containment
  • Customer notification within 72 hrs of confirmed breach (GDPR Art. 33)
  • Post-incident review & root cause analysis within 5 business days

Responsible Disclosure

  • Report to: [email protected]
  • PGP key available on request
  • Safe harbour: good-faith research protected
  • Hall of Fame for validated reports
  • Response within 5 business days

Security Contact

  • Email: [email protected]
  • Entity: PirateApeStudios (ABN 47 340 546 246)
  • Jurisdiction: Western Australia, Australia

Ready to try XrayFlow?

Experience our privacy-first, ephemeral architecture yourself. Connect your Make.com account in seconds.

Get Started Free
TLS 1.3 EncryptionAll data in transit encrypted with TLS 1.3
Stripe PCI-DSS Level 1Payments processed by Stripe (PCI-DSS Level 1 certified)
Hosted on Vercel (SOC 2, ISO 27001)Vercel infrastructure: SOC 2 Type II, ISO 27001 certified
GDPR & CCPA CompliantFull GDPR Art. 28 DPA available, CCPA rights supported

© 2026 Xray Flow. Not affiliated with Make.com.

All rights reserved. XrayFlow is a product of PirateApeStudios (ABN 47 340 546 246)

AboutPricingResourcesContactSecurityDPADMCAPrivacy PolicyTerms of Service