Security

Security controls you can check for yourself.

PrimesFlow has visibility into your servers, so we're deliberate about what we ask you to trust us with. This page describes the controls in place today, without marketing spin or forward-looking promises.

TLS-encrypted transport

The agent connects to PrimesFlow over TLS, and all metric samples, service state, and incident payloads travel over HTTPS with modern cipher suites.

Unprivileged, outbound-only agent

The agent runs as an unprivileged systemd service, opens no inbound ports, and needs no firewall changes — outbound HTTPS is all it requires.

Operational-metrics-only data boundary

PrimesFlow collects host and service telemetry — CPU, memory, disk, network, systemd/container state, and error-log signals — and does not read your application source, request bodies, database rows, or end-user data.

Access controls at the account level

Workspaces keep hosts and dashboards isolated. Team-plan workspaces layer on role-based access control (Owner / Admin / Member / Viewer) so contractors and junior staff see only what they need to.

Configurable retention

Raw metric retention follows your plan: 7 days on Hobby, 30 on Pro, 90 on Team. Deleting a workspace clears its metric history from the primary store on the schedule described in our privacy policy.

PCI DSS Level 1 payment handling

Card data is handled entirely by a PCI DSS Level 1 certified payment provider — PrimesFlow's own servers never see raw card numbers.

About certifications

PrimesFlow does not currently hold SOC 2, ISO 27001, or HIPAA certification. We only describe controls we've actually implemented. If your procurement process needs an attested audit report today, PrimesFlow probably isn't the right fit yet — we'd rather tell you that directly than hand you a compliance sheet that overstates where we are.

How the agent connects to your servers

  • • Installed as a systemd service under a dedicated unprivileged user.
  • • Requires only outbound HTTPS (TCP/443) to ingest.primesflow.io. No inbound ports opened on your host.
  • • Authenticates with a per-workspace token you can rotate at any time from the dashboard.
  • • Reads host-level metrics from /proc, /sys, systemd's D-Bus interface, and the Docker socket if present. Does not read from /home, /var/lib application directories, or your source tree.
  • • Buffers samples locally during a network partition and flushes them in order when connectivity returns.

Reporting a security issue

If you think you've found a security issue in PrimesFlow, email us at contact@primesflow.io with reproduction steps and, if possible, a proof-of-concept. We'll acknowledge within two business days.

Questions we haven't answered? Talk to us before you sign up.