Security & compliance
Security controls for your embedded engineering data.
The controls and practices that keep customer schematics, firmware, and project data safe at Flash.
Last reviewed · August 2026
Security practices
Encryption
TLS for data in transit and encryption at rest. Customer secrets are isolated in a managed secret store, never embedded in code or images.
Access control
SSO with mandatory MFA. Production access is role-based, least-privilege, and time-bound, with privileged actions reviewed and audited.
Monitoring & audit
Centralized audit logging across identity, secrets, and infrastructure, with alerting on anomalous activity and documented incident response.
Change management
Infrastructure and application changes go through peer review, automated checks, and a tested rollback path. No direct production access.
Vulnerability management
Automated dependency, code, and secret scanning on every change. Findings are tracked to remediation and dependencies are pinned for reproducible builds.
Backup & recovery
Continuous backups with point-in-time recovery, versioned storage, and tested restore procedures.
Deployment and data boundary
Deterministic local analysis
Project ingestion and context construction run without an LLM, producing inspectable artifacts before inference.
Provider control
Teams select the model endpoint and can keep inference on local or privately hosted infrastructure.
Air-gapped option
The product workflow can be evaluated for environments where outbound model and telemetry connections are not permitted.
See the product-level engineering data boundary for the inputs kept inside the environment.
Security review
Reviewing Flash for your team
Send us your security questionnaire, or tell us the deployment model you need to evaluate — including fully air-gapped — and we'll walk your team through the controls under NDA. Review the local and air-gapped deployment architecture before the session.