Skip to main content
About Akiflow

Security

The full regulation on how we process your data is outlined in our terms and conditions and in our privacy policy. Please refer to those in case of doubt. The following page is intended as a quick reference on the essential principles that govern our data policies.


Useful Resources


Vulnerability Disclosure

Policy

Your privacy and data security are crucial to us at Akiflow, and we constantly work to identify weaknesses in our technology.

The responsible disclosure of security vulnerabilities helps us ensure the security and privacy of our systems, our customers and their data.

If you believe you've found a security issue in our product or service, we encourage you to notify us. We welcome working with you to resolve the issue promptly.

Disclosure Policy

  • Let us know as soon as possible upon discovering a potential security issue, and we'll make every effort to resolve the problem quickly.

  • Please provide us with a reasonable amount of time to resolve the issue before any disclosure to the public or a third party.

  • Make a good faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our service. Only interact with accounts you own or with the explicit permission of the account holder.

While researching, we'd like to ask you to refrain from:

  • Denial of service

  • Spamming

  • Social engineering (including phishing) staff or contractors

  • Any physical attempts against Akiflow property or data centres

Bounty program

Currently, Akiflow does not officially ensure any bounty for found bugs, but if you believe you've found a security issue with Akiflow, please tell us so we can address it. Your efforts may be eligible for a monetary reward.

You may be eligible for a monetary reward if you are the first person submitting a bug and you comply with all the rules listed in this document.

Out-of-scope vulnerabilities

  • Anything that's on any domain different than akiflow.com, app.akiflow.com and api.akiflow.com and the desktop client.

  • Dynamic XSS, unless chained with other exploits.

  • Open redirect issues unless chained with other exploits.

  • Network-level Denial of Service (DoS/DDoS) attacks

  • Spam-related issues

  • Issue affecting third parties (Chargebee, Intercom, postmark, etc.)

  • UI and UX bugs (i.e., copy errors, spelling mistakes)

  • Other non-security related bugs

  • Findings from physical testing (i.e., at offices, following employees, etc.)

Feel free to reach out to report the problems mentioned above, but most likely, we will not recognize any monetary reward for it.

How you should behave while looking for bugs

  • Delete any test data or accounts you have created as part of the research. (if possible)

  • Don't attack or interact with end-users.

  • Don't engage with stolen user data, including credentials.

  • Don't use social engineering attacks, such as phishing.

Reporting

If you believe you have found a security vulnerability, please report it by emailing support@akiflow.com.

  • Please include a detailed description and potential impact of the vulnerability with the steps required to reproduce the vulnerability, highlighting the security impact. (POC scripts, screenshots and videos are all helpful).

  • Your submission should include instructions for reproducing the vulnerability (written or video). Reports without clear reproduction steps may be ineligible for a reward.


FAQ

  • Your Akiflow account, contact information, and your billing information.

  • Data such as, but not limited to, your tasks, labels and other elements created in Akiflow.

  • Data coming from third-party sources relevant to Akiflow (like calendar events, the subject of the emails you star, or the text of slack messages you save).

  • API keys and authorization tokens to access data on third-party sources.

We are doing so to provide you with additional features, such as:

  • multiple device synchronization support

  • recovery in case of data loss from your device

That means that data such as, but not limited to, your tasks, events, or saved Slack messages is stored on your local machine and synced with our servers.

To ensure the highest degree of security relative to the Service provided, we take several measures to protect all data we process. These measures include, but are not limited to:

  • User’s contact information (such as name, email, etc.) and user-generated data (such as tasks, events, etc.) are stored in several different databases, on different servers.

  • Access to the servers, and the databases hosted on such servers, is granted only to individual high-level employees, only to the extent needed to maintain and develop the service, and is subject to rigorous authentication mechanisms.

  • We use techniques such as data pseudonymization, the unique identifiers for each user and their data are stored on different databases on different servers.

We implement strong encryption mechanisms. All communications are encrypted using https protocol (TLS). In transit, we use TLS. Regarding API keys and authorization tokens. At rest, data is encrypted using industry-standard 256-bit AES encryption on our servers. Our infrastructure use GCP, and databases are stored at rest, according to GCP policies.

Internally we follow a minimum access policy to share data. Authentication is linked to GCP and Google accounts to ensure access to personal data.

We currently don’t have these certifications.

Yes, please send our Support team a message in order to get a DPA signed.