Security at XrayFlow
Trust is our product. Here is exactly how we handle your data.
1. The "Ephemeral" Promise
XrayFlow is designed as a Client-Side Proxy.
- No Storage: Your Make.com API Key is never written to a database. It is stored in your browser's encrypted session memory and sent to our server only for the duration of the request.
- Volatile Memory: Once your report is generated, the key is flushed from our server's RAM.
2. Infrastructure
- Hosting: We are hosted on Vercel (Australia), utilizing their secure, ISO-certified serverless infrastructure.
- Encryption: All data in transit is encrypted via TLS 1.3 (Bank-Grade Encryption).
- WAF: We are protected by Cloudflare Enterprise-grade DDoS protection.
4. Live Blueprint Analysis
See our engines analyze your actual workflow in real time.
Paste a blueprint or load a scenario to run Xray Flow's full engine suite: security & resilience scoring, data flow & PII mapping, compliance checks (GDPR/CCPA), and module configuration extraction.
Two processing modes:
- Local blueprint analysis: If you paste or upload a blueprint, analysis runs entirely in your browser via our Rust WASM engine. No data leaves your browser.
- Connected Make retrieval: When you connect your Make.com account or provide an API key, the key is transmitted over TLS to retrieve the selected scenario and is not persistently stored.
5. Data Privacy
- Your Intellectual Property: We do not claim ownership of your blueprints.
- No Training: We do not use your blueprints to train AI models.
6. Security Architecture & Data Flow
XrayFlow implements a privacy-by-design architecture with two distinct processing modes. The diagrams below illustrate how data flows through each mode and the security controls at each layer.
Mode 1: Local Blueprint Analysis
Paste or upload a blueprint — zero server interaction
1. Blueprint Input
User pastes JSON or uploads .json file in browser
2. Client-Side Parsing
Rust WASM engine parses blueprint in browser memory
3. Analysis Engines Run
Security, data flow, compliance, module extraction — all local
4. Report Generated
Diagram, documentation, audit findings created in browser
5. User Exports/Downloads
PDF, DOCX, Markdown downloaded directly — no server upload
Mode 2: Connected Make.com Retrieval
Connect Make.com account — ephemeral server-side fetch
1. API Key Entry
User provides Make.com API key (stored in browser encrypted session)
2. Scenario Selection
User selects scenario from their Make.com account via UI
3. Ephemeral Server Fetch
API key sent over TLS to server → fetches scenario → key flushed from RAM
4. Client-Side Analysis
Blueprint sent to browser → WASM engines run locally (same as Mode 1)
5. Report Generated & Exported
Results created in browser, downloaded directly
Data Protection
- TLS 1.3 for all transit
- Web Crypto API for client encryption
- No blueprint persistence
- API keys: encrypted session storage
Infrastructure
- Vercel (Australia) — ISO 27001, SOC 2
- Cloudflare Enterprise WAF & DDoS
- Serverless — no persistent servers
- CSP, HSTS, COOP, CORP, COEP headers
Data Retention & Access
- Account data: 90 days post-deletion
- Billing: 7 years (tax law)
- Analytics: 13 months (opt-in)
- Blueprints: never stored
7. AI Data Processing & Provider Disclosures
XrayFlow offers optional AI-powered insights (architecture review, improvement suggestions) as a Pro feature. When enabled, the following applies:
What Data Is Sent to AI Providers
- Blueprint structure (module types, connections, names)
- Security findings summary (no raw secrets)
- Module configuration parameters (sanitised)
- Raw API keys, credentials, or PII — never sent
Provider & Model
- Provider: Google (Gemini) via Vertex AI
- Model: Gemini 1.5 Pro / Flash
- Region: Australia (Sydney) / US (configurable)
Data Retention & Training
- Google does not use your data to train models (Vertex AI data governance)
- Prompts & responses logged for 30 days for abuse monitoring only
- No XrayFlow staff access to AI conversation logs
User Controls
- AI insights are opt-in (Pro only, disabled by default)
- Can be disabled anytime in Settings → AI Settings
- Per-analysis toggle: run with or without AI
Frequently asked questions
Where is my Make.com API key stored?
Your API key is never written to a database. When you connect your Make.com account, the key is stored in your browser's encrypted session memory and sent to our server only for the duration of the request to retrieve your scenario, then flushed from RAM. For local blueprint analysis (pasted JSON), no API key is needed and no data leaves your browser.
Do you store my blueprints or scenarios?
No. Blueprint processing is ephemeral — we do not retain your scenarios after your report is generated. For local analysis, the blueprint never leaves your browser. For connected Make retrieval, the blueprint is fetched, processed in-memory, and discarded.
Do you use my data to train AI models?
No. We do not use your blueprints to train AI models. AI insights (where enabled) are generated via third-party providers with their own data retention policies — see our Privacy Policy for details.
How is my data encrypted?
All data in transit is encrypted with TLS 1.3. We are hosted on Vercel (Australia) with Cloudflare Enterprise DDoS protection. Local browser analysis uses Web Crypto API for any client-side encryption operations.
Is Xray Flow affiliated with Make.com?
No. Xray Flow is an independent tool and is not affiliated with Make.com.
8. Incident Response & Vulnerability Reporting
We take security incidents seriously and have established processes for detection, response, and responsible disclosure.
Incident Response
- 24/7 monitoring via Vercel & Cloudflare alerts
- Incident classification: SEV-1 (critical) to SEV-4 (low)
- SEV-1 response: <15 min acknowledgement, <1 hr containment
- Customer notification within 72 hrs of confirmed breach (GDPR Art. 33)
- Post-incident review & root cause analysis within 5 business days
Responsible Disclosure
- Report to: [email protected]
- PGP key available on request
- Safe harbour: good-faith research protected
- Hall of Fame for validated reports
- Response within 5 business days
Security Contact
- Email: [email protected]
- Entity: PirateApeStudios (ABN 47 340 546 246)
- Jurisdiction: Western Australia, Australia