Tenant isolation
Every query, export, webhook, and cache key is scoped to the workspace. There is no shared “maybe this org” path.
MeetFlow is built for SOC 2 and ISO 27001 programs. We do not display those marks until an independent audit is complete.
Every query, export, webhook, and cache key is scoped to the workspace. There is no shared “maybe this org” path.
Mail, calendar writes, and provider calls recover without a silent double-send or a second hold on the same slot.
Card data never touches MeetFlow servers. Stripe Elements and Connect collect; we store a reference, not a PAN.
Invitee PII can be exported or deleted. Booking pages collect only what the event type asks for.
SAML and SCIM via WorkOS when Enterprise entitlements are on. Roles already exist on every paid seat.
TLS in transit. Secrets and OAuth tokens encrypted at rest. Tokens do not appear in application logs.
Hosts, invitees, booking times, and the answers on your form. Calendar titles from connected accounts stay in the availability engine — they are not shown on analytics walls. We do not sell invitee lists.
A seat is anyone who hosts or is assigned meetings. Invitees never need one. Public booking pages must not be used to collect payment for unlawful goods. Questions: hello@appointment.bukka.ai.