Built so that we cannot see your data.
WorkFlura has two parts. Your organization's data plane is a Google Cloud project you create and own. Scultura's control plane holds only what is needed to run the service: which organizations exist, what they are licensed for, and how they are configured. This page describes the controls that keep it that way.
Data custody
Your data plane
Users, organizational units, roles, workflow definitions, submissions, approvals, attachments, reports, and error detail live in a Firebase / Google Cloud project that your organization creates. You choose its region. You can inspect, query, back up, export, or delete everything independently of Scultura, and it remains yours if you stop using WorkFlura.
Our control plane
A Google Cloud project operated by Scultura in the Mumbai (asia-south1) region. It holds the organization registry, license and billing status, configuration, session records, error signals that contain no personal data, and aggregate adoption counts mirrored no more than once a day. It does not hold workflow content.
How WorkFlura reaches your project
Through a service account that your organization creates in its own project. Its key is encrypted at rest on our side, decrypted only in memory when a request needs it, and never written to logs. Revoking the key in your own Google Cloud console ends WorkFlura's access immediately.
Identity and permissions
Google Sign-In only
WorkFlura stores no passwords. Every user is a Google Workspace identity, and every action is attributed to that identity.
Two permissions at sign-in
forms.body to create and configure forms built from the designer, and drive.file to manage only the files WorkFlura created or you explicitly attach. The sign-in token stays in your browser session; Scultura does not store Google access or refresh tokens.
Four delegated scopes, no restricted scopes
Your Workspace administrator authorizes your own service account for exactly four scopes: forms.body, forms.responses.readonly, drive.file, and admin.directory.user.readonly. None is a Google restricted scope. WorkFlura cannot browse your Drive, read forms it did not create, or write to your directory. The authorization can be reviewed or withdrawn at any time in the Google Admin console.
Role-based authority
Standard users submit and approve. Pro users additionally design workflows and see organization metrics. System Administrators manage users, seats, billing, and policies for their own organization only. Scultura staff cannot reach one organization's data through another's console.
Protection in operation
Encryption
All traffic uses HTTPS. Service-account keys and shared secrets are encrypted at rest; deployment secrets are held in Google Secret Manager.
Deny-by-default rules
WorkFlura publishes Firestore and Cloud Storage security rules into your project that deny everything except rule-scoped reads of a user's own records. All business operations go through WorkFlura's service, which authenticates every request and applies role checks before touching your data.
Verified internal calls
Background work — form notifications, SLA timers, archival, reports — is carried by Google Cloud Tasks and Pub/Sub with signed identity tokens verified against the expected service account and audience.
Tamper-evident audit trail
Every approval decision is tied to a Google-authenticated identity and a timestamp and written to a log that end users cannot alter. Support access and platform configuration changes are logged too.
Retention you control
Workflow content is retained in your project for as long as you keep it, with archival on a schedule you set. Form responses are purged from the Google Form itself, by a script running inside your Workspace, once WorkFlura has processed them. Control-plane sessions expire after 15 hours; error signals and job records carry automatic time-to-live deletion.
Support without a back door
Diagnostics first
Built-in readiness and health checks work without any access to your data, for your administrators and for us.
Access only by consent
If a case needs a look inside your project, your System Administrator grants time-limited, read-only support access from the Admin Console. The grant has a maximum duration you set, can be revoked at any time, and every access under it is logged in your own project.
Breach notification
No system is perfectly secure. If we become aware of a breach affecting your organization's information, we notify your System Administrator without undue delay.
Payments and this website
Card details never reach us
Subscriptions are sold by Paddle, our Merchant of Record. Paddle collects payment details, calculates tax, and issues invoices; Scultura receives only customer and subscription identifiers, plan, amount, and status.
No trackers, no cookies
This website sets no cookies and loads no analytics or advertising scripts. Fonts are served from this site, not from a third party.
The full description of what we collect and why is in the Privacy Policy. WorkFlura's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Security questions: support@sculturats.com