← Back to LP

SECURITY AND PROCUREMENT

Security and adoption materials

This page lists materials to review before adopting NinjaFlow and their current availability. It does not guarantee contract terms, retention periods, an SLA, an audit conclusion, or an individual environment.

Current security posture

The following points describe the current configuration and data-handling controls available for adoption review.

Allowed email domains for company accounts

An owner can configure the email domains allowed for a company account. Domains are checked both when an invitation is sent and when a person joins, and email addresses that do not meet the setting are not accepted. Changes can be reviewed before they are saved.

Project-level visibility separation

A setting can enable information to be shown separately by project. Owners and administrators can view all projects for necessary administration. When support staff review all projects, the operation is recorded.

Encryption in transit and at rest

Encryption is used for communications and for storage managed by the underlying platform. Additional encryption with keys managed by us is limited to recovery archives.

Complete tenant deletion

Complete deletion by tenant cannot currently be performed from this service. Retention and deletion conditions are explained before adoption after reviewing the intended environment and contractual requirements.

Adoption materials

Only published materials can be opened from this page. Items in preparation or not offered are not presented as published documents.

Data Processing Agreement (DPA)

A contract attachment for reviewing data-processing terms for an individual engagement. It is not a standard published document and is available only when an individual contract is agreed.

In preparation

Scope
Data-processing terms agreed in an individual contract
Plans
Business · Enterprise
Regions and availability
Confirmed individually
Delivery
Individual contract attachment
Last reviewed
2026-07-23

This is not a promise of standard availability.

Retention and deletion information

Material for reviewing retention periods, deletion, and how deletion scope is confirmed. A formal public document is in preparation.

In preparation

Scope
Retention and deletion by contract, configuration, and intended environment
Plans
Business · Enterprise
Regions and availability
Confirmed individually
Delivery
Secure delivery after review
Last reviewed
2026-09-10

This catalogue does not guarantee a retention period.

Subprocessor information

Material for reviewing how data-processing subprocessors are identified, including managed AI inference provider changes. No published list is currently available.

In preparation

Scope
Subprocessor information reviewed in individual contracts and use conditions
Plans
Business · Enterprise
Regions and availability
Confirmed individually
Delivery
Secure delivery after review
Last reviewed
2026-07-23

Anthropic and OpenAI AI-inference entries remain under legal review. This does not represent a published subprocessor list.

SLA and support-scope information

Material for individually reviewing service levels and support scope. NinjaFlow does not present an SLA as a standard offering.

Not offered

Scope
Service levels and support conditions agreed individually
Plans
Business · Enterprise
Regions and availability
Confirmed individually
Delivery
Individual contract attachment
Last reviewed
2026-07-23

A standard SLA is not offered.

Operation-record and audit-related information

Material that distinguishes generation history, customer-facing operation records, and NinjaFlow internal developer records. A formal public document is in preparation.

In preparation

Scope
Review of record purpose, access scope, and retention conditions
Plans
Business · Enterprise
Regions and availability
Confirmed individually
Delivery
Secure delivery after review
Last reviewed
2026-07-23

This does not promise audit trails or audit reports.

Project separation and individual-operation information

Material for reviewing the project-level separation setting and the boundary between the NinjaFlow managed service and customer-managed or individual environments. A formal public document is in preparation.

In preparation

Scope
Requirements for individual environments, customer-managed AI, and customer-managed storage
Plans
Business · Enterprise
Regions and availability
Confirmed individually
Delivery
Secure delivery after review
Last reviewed
2026-09-10

This does not promise individual environments or data separation as standard features.

Operating company

NinjaFlow is operated by the Japanese entity identified below.

Operating entity
San Space Japan G.K.
Representative
Masaki Kitagawa
Registered address
Nishishinbashi Dai-ichi Hoki Building 2F, 3-5-2 Nishishinbashi, Minato-ku, Tokyo 105-0003, Japan
Date of establishment
August 27, 2025
Company website

How records are separated

Workspace generation history

  • Viewing is limited to users of the relevant workspace.
  • Generation-history retention is targeted at 90 days. Confirm actual retention before adoption.
  • The record includes an execution ID, status, stage, elapsed time, model, language, output counts, and fixed diagnostic metadata.
  • It does not include source text, attachment filenames, URLs, generated artifacts, or raw provider errors.

NinjaFlow internal developer records

For service operations, developers may review limited administrative records. This is NinjaFlow internal operation, not a customer-facing feature, report, or audit report.

Customer-facing operation records

The scope, export method, and retention conditions for records visible to customers are organized after reviewing the intended environment and contractual requirements. They are not promised as a standard feature.

Boundary between the NinjaFlow managed service and individual operation

The standard NinjaFlow managed service is not the same offering as customer-managed AI, customer-managed storage, or a dedicated or individual environment. Individual operation requires requirements definition and individual quotation after reviewing connectivity, responsibility boundaries, operating, and audit requirements.

Encryption in transit

Each service communicates with the database and storage (Supabase) over HTTPS (encrypted in transit).

Official consultation intake

For adoption and pre-contract questions, review the official consultation intake, including its purpose, retention approach, and notification scope.

Review official consultation intake

Individual data-handling consultation

The individual data-handling consultation channel is in preparation. This page does not accept requests until a channel is configured.