Draft — for qualified legal review
This notice is published as a draft pending qualified legal review in each jurisdiction where Flow Group Ventures operates. It is provided for transparency about the group's operating posture and does not itself constitute legal advice.
Scope
This overview summarises the group's information-security posture across internal systems and engagement delivery. It does not itself constitute an independent security attestation.
Controls summary
Applied across internal systems and engagement delivery.
- Identity and access management with role-based access
- Least-privilege access to client data
- Endpoint and device baseline controls
- Encryption in transit for data movement
- Vendor review before onboarding
- Documented incident response and escalation
Vulnerability reporting
Suspected vulnerabilities can be reported via the contact channel. Reports are acknowledged and triaged under the group's incident response process. Please do not publicly disclose suspected issues before they are addressed.
Governing statement
Flow Group Ventures structures relevant engagements around the commercial, privacy, employment, marketing, technology, contractual, and data requirements applicable to the client, service, and jurisdiction. Where an engagement requires licensed, regulated, or jurisdiction-specific advice, Flow Group Ventures may coordinate with qualified local professionals or require the client to obtain appropriate advice.