Trust and product data
Last reviewed: 26 July 2026
Solo project data stays on the device running the app, and there is no product-data cloud sync today. Everything below separates what is shipped from what is planned. This is a product status summary, not a certification or a security audit.
What is shipped, and what is planned
Private pilot
Available now
- Solo project data is held on the user’s device.
- The desktop application works without cloud sync.
- Project content is not used to train or evaluate AI models.
- Reports can be exported from the application.
Roadmap
Not yet available
- Encrypted backup and cross-device sync.
- Multi-user cloud collaboration and Web View.
- Self-hosted Enterprise deployment.
- SSO/SAML and a formal security-review package.
Current data flow
In the Solo private pilot, Table 1 project data remains on the device running the desktop application. There is no product-data cloud sync. Website enquiries are separate from product data and are handled as set out in the Privacy Policy.
Data ownership, portability and exit
Your criterion responses, evidence and project records are your data. The product is designed to export the report so it can be retained outside TableOne Flow. Export capability does not replace your own records-management, backup or retention procedures. Enterprise exit and continuity terms will be agreed only when that offering is available.
AI use
TableOne Flow does not use customer Table 1 content, evidence or audit records to train or evaluate AI or machine-learning models. The educational pages on this website do not expose private customer data or the product’s private prompt and rule sets.
Planned cloud controls
Optional encrypted backup, Australian-region hosting, cross-device sync, Web View and multi-user collaboration are planned, not active. Their architecture, processors and operating controls will be documented after implementation evidence exists and before the relevant service is made available. Roadmap statements are not delivery commitments.
Certifications and assurance
TableOne Flow does not currently claim SOC 2, ISO 27001 or IRAP certification. It also does not claim that the software is certified by JORC, ASX or ASIC. A product cannot determine whether a particular Public Report is adequate; that responsibility remains with the company and the appropriately qualified professionals involved.
Report a vulnerability
We welcome reports of security issues in TableOne Flow or in this site.
- How to report. Use the contact form and begin your message with “Security report” so it is routed rather than read as a sales enquiry. Describe the affected surface first and leave out exploit detail — we will arrange a private channel for that in our reply.
- Acknowledgement. Within five business days.
- Good-faith research. We will not pursue legal action against researchers who act in good faith, stay within the limits below, and give us reasonable time to respond before disclosing.
- Credit. We will credit you in release notes if you want us to.
- Bug bounty. We do not run one.
Non-production environments are in scope for good-faith testing. Please keep to passive, unauthenticated observation of app.tableoneflow.com: it holds customer project data, some of which has not been publicly released, so never access, modify or retain another party’s data. Ask us before running automated scanning or any denial-of-service test against a TableOne Flow environment. We ask for 90 days before public disclosure and will tell you when a fix has shipped.
Procurement questions
If you need to discuss deployment boundaries, jurisdiction, data handling or a future vendor assessment, describe your requirements. We will distinguish current evidence from intended design in our response.