FLASH

Security & compliance

Security controls for your embedded engineering data.

The controls and practices that keep customer schematics, firmware, and project data safe at Flash.

Last reviewed · August 2026

Security practices

Encryption

TLS for data in transit and encryption at rest. Customer secrets are isolated in a managed secret store, never embedded in code or images.

Access control

SSO with mandatory MFA. Production access is role-based, least-privilege, and time-bound, with privileged actions reviewed and audited.

Monitoring & audit

Centralized audit logging across identity, secrets, and infrastructure, with alerting on anomalous activity and documented incident response.

Change management

Infrastructure and application changes go through peer review, automated checks, and a tested rollback path. No direct production access.

Vulnerability management

Automated dependency, code, and secret scanning on every change. Findings are tracked to remediation and dependencies are pinned for reproducible builds.

Backup & recovery

Continuous backups with point-in-time recovery, versioned storage, and tested restore procedures.

Deployment and data boundary

Deterministic local analysis

Project ingestion and context construction run without an LLM, producing inspectable artifacts before inference.

Provider control

Teams select the model endpoint and can keep inference on local or privately hosted infrastructure.

Air-gapped option

The product workflow can be evaluated for environments where outbound model and telemetry connections are not permitted.

See the product-level engineering data boundary for the inputs kept inside the environment.

Security review

Reviewing Flash for your team

Send us your security questionnaire, or tell us the deployment model you need to evaluate — including fully air-gapped — and we'll walk your team through the controls under NDA. Review the local and air-gapped deployment architecture before the session.

Contact us