Security at XrayFlow
Trust is our product. Here is exactly how we handle your data.
1. The "Ephemeral" Promise
XrayFlow is designed as a Client-Side Proxy.
- No Storage: Your Make.com API Key is never written to a database. It is stored in your browser's encrypted session memory and sent to our server only for the duration of the request.
- Volatile Memory: Once your report is generated, the key is flushed from our server's RAM.
2. Infrastructure
- Hosting: We are hosted on Vercel (Australia), utilizing their secure, ISO-certified serverless infrastructure.
- Encryption: All data in transit is encrypted via TLS 1.3 (Bank-Grade Encryption).
- WAF: We are protected by Cloudflare Enterprise-grade DDoS protection.
4. Live Blueprint Analysis
See our engines analyze your actual workflow in real time.
Paste a blueprint or load a scenario to run Xray Flow's full engine suite: security & resilience scoring, data flow & PII mapping, compliance checks (GDPR/CCPA), and module configuration extraction — all client-side, no data leaves your browser.
Run Live Analysis5. Data Privacy
- Your Intellectual Property: We do not claim ownership of your blueprints.
- No Training: We do not use your blueprints to train AI models.
Frequently asked questions
Where is my Make.com API key stored?
Your API key is never written to a database. It lives in your browser's encrypted session memory and is sent to our server only for the duration of the request, then flushed from RAM.
Do you store my blueprints or scenarios?
No. All blueprint processing is ephemeral — we do not retain your scenarios after your report is generated.
Do you use my data to train AI models?
No. We do not use your blueprints to train AI models.
How is my data encrypted?
All data in transit is encrypted with TLS 1.3. We are hosted on Vercel (Australia) with Cloudflare Enterprise DDoS protection.
Is Xray Flow affiliated with Make.com?
No. Xray Flow is an independent tool and is not affiliated with Make.com.