SECURITY & TRUST CENTER
Security built into every layer of your company’s work.
MCD Flow protects workspace access, company separation, permissions, files, client visibility, and administrative operations through controls designed for modern AEC teams.
Access, permissions, privacy, and traceability.
SECURITY PRINCIPLES
Clear, responsible protection aligned with AEC work.
We explain the platform’s real controls without absolute promises or certifications that do not apply.
Company separation
Each workspace keeps users, projects, files, messages, estimates, contracts, and invoices associated with its own company.
Responsibility-based access
Permissions are assigned according to each person’s role and responsibilities inside the team.
Controlled client visibility
The company decides which files, messages, approvals, updates, and financial documents are shared.
No automatic support access
Technical support does not receive unrestricted workspace access; users may authorize limited, temporary access.
TENANT & PERMISSIONS
Every company keeps its own operating context.
MCD Flow associates users, projects, files, conversations, costs, and settings with the appropriate workspace. Sensitive actions must validate identity, tenant context, and permissions before displaying or changing information.
- One company should not view another company’s information.
- Members access features according to their role and assignments.
- Desk users remain separated from administrative users.
CLIENT VISIBILITY
Keep clients informed without exposing internal work.
Share only what is needed for collaboration: selected files, messages, approvals, invoices, and updates. Internal conversations, costs, margins, markups, and team coordination can remain private.
OPERATIONAL CONTROLS
Protection from sign-in through support.
Verified accounts
Required email verification for tenant accounts and secure recovery for expired links.
Reinforced admin access
Six-digit codes and separate routing for WordPress administrative users.
Protected public forms
Cloudflare Turnstile, nonces, honeypots, rate limiting, sanitization, and server-side validation.
Project-bound files
PDFs, images, videos, markups, and comments remain associated with project access and permissions.
Secure connections
The platform is served through HTTPS and validates public, Desk, and administrative requests.
Temporary support access
Users may authorize limited scope and duration, then revoke permission before expiration.
PRIVACY & DATA
Your company remains in control of its information.
MCD Flow supports consent records, legal versioning, privacy requests, and controlled support workflows. Workspace export and secure deletion controls will continue to expand as part of the product’s evolution.
Review privacy →PAYMENTS
Payments are processed through Stripe.
MCD Flow does not need to store full card details inside the application. Subscription and payment workflows are processed through Stripe.
SHARED RESPONSIBILITY
Security also depends on each workspace’s decisions.
Use unique passwords and verified email addresses.
Assign roles according to real responsibilities.
Promptly remove former team members.
Limit client visibility to what is genuinely needed.
Do not share passwords, payment data, or confidential documents through public forms.
Report suspicious activity through a private support ticket.
RESPONSIBLE DISCLOSURE
Have a security or privacy concern?
Submit a private inquiry through Contact. If you already use MCD Flow, open a secure ticket inside Help & Support to preserve the case history.
SECURITY WITHOUT INFLATED CLAIMS
Real controls for a platform that continues to evolve.
Explore MCD Flow without a card, upfront payment, or commitment to continue.
