Documentation Get help

Cloud Proxy security and privacy

This page is for the security, privacy and compliance people who decide whether to roll out the Cloud Proxy. It describes what happens today.

In short

  • On a Mac with the Flowstate agent, conversations with covered AI services go through the Flowstate Cloud Proxy at proxy.flowstate.inc.
  • The Cloud Proxy records each request and response in full: prompts, responses, files and request headers. Headers can include the AI tool’s own API key or sign-in token.
  • Recorded requests are kept in your organisation’s data region and deleted after 30 days.
  • In Flowstate, people see a session for each conversation — a short title and summary, the tool, model, cost and project — not the conversation itself.
  • Traffic to anything other than a covered AI service isn’t sent to the Cloud Proxy.

What is recorded

For every request a covered AI tool makes:

WhatDetail
WhenThe time, how long it took, and how long until the first response
WhoThe Mac’s assigned user’s email, from your device management tool, and your organisation
WhereThe AI service’s address, and the request method and path
Which toolIdentified from the tool’s own user agent
OutcomeThe response status
HeadersAll request and response headers. These can include the AI tool’s own API key or sign-in token
ContentThe full request and response: prompts, responses, tool calls, and any files sent with the request

What isn’t recorded

  • Connections to anything other than a covered AI service. They don’t go to the Cloud Proxy.
  • Anything on the Mac itself. The agent passes covered connections on without reading them, and doesn’t store them on the Mac.
  • AI services that aren’t covered, such as GitHub Copilot and Windsurf, and AI use on Windows or Linux computers.

What Flowstate keeps from it

Flowstate reads the recorded requests and builds a session for each conversation:

  • a short title and a one-line summary of what the session was about;
  • a category, such as Feature, Bug Fix or Documentation;
  • the tool, model, tokens used and estimated cost;
  • the project, initiative and pull requests it’s tied to;
  • signals raised against it, such as an API key or customer data detected. A signal keeps only a masked version of what matched, never the text around it.

Sessions categorised as Personal / Sidetracked keep no title or summary. They show in Flowstate as Personal session.

Where it’s kept, and for how long

WhereHow long
Recorded requestsFlowstate’s storage in your organisation’s data regionDeleted 30 days after they’re recorded
SessionsFlowstate, in your organisation’s data regionNo set period. Agree a retention period with your Flowstate contact if you need one

Your data region is Europe, United Kingdom, United States or Australia. It’s shown at the bottom of your Flowstate sign-in page.

Who can see it

In Flowstate

  • Sessions: once AI attribution is switched on, anyone with a Flowstate account in your organisation can open Insights → Agent insights → Agent sessions and see every session — its title, summary, person, tool, cost and project. The exception is people with the AI Viewer role, who only see their own My AI page.
  • Their own sessions: everyone sees their own under My AI → My sessions.
  • Recorded conversations: no Flowstate screen shows the full prompts and responses.

At Flowstate

Recorded requests and sessions are held in infrastructure Flowstate operates. Access by Flowstate staff is governed by your agreement with Flowstate.

Your organisation’s certificate

To read covered conversations, the Cloud Proxy needs your Macs to trust a certificate that belongs only to your organisation, Flowstate Tenant CA.

  • The profile you deploy puts the public certificate on your Macs. Flowstate keeps the private key.
  • No other organisation’s Macs trust your certificate, and your Macs don’t trust anyone else’s.
  • Removing the Flowstate profile from a Mac removes the trust.

Your organisation’s token

Every Mac identifies itself with its user’s email and one token shared by your whole organisation. The token is inside the profile, lasts one year and can be replaced. Keep the profile file private. See Replace the Cloud Proxy token and other keys.

What people using the Macs see

  • A Flowstate icon in the menu bar.
  • No consent screen and no prompts. Recording starts once the agent and its profiles are installed.
  • Their AI tools work as before.

Telling people is up to you. Agree the wording with HR and, where they apply, works councils or employee representatives, and send it before the pilot.

What AI providers see

  • The same request the tool sent, including the tool’s own API key or sign-in. Flowstate doesn’t change or replace credentials.
  • Requests arrive from Flowstate’s network rather than your offices. See Allow the Cloud Proxy through your network.

Before you approve

Settle these before the pilot:

  1. Recording: you accept that full prompts, responses, files and headers are recorded for 30 days.
  2. API keys: you’re comfortable that provider API keys used on company Macs appear in recorded headers.
  3. Access: you’ve decided who in your organisation may see sessions, and given everyone else the AI Viewer role.
  4. Retention: you’ve agreed how long sessions are kept.
  5. Notice: people have been told, in writing, before their Mac gets the agent.
  6. Shared Macs: shared Macs are left out, because every session on a Mac goes against its one assigned user.