Role-based workspace access
Owner and staff permissions keep workspace, team, integration, and finance controls with the people expected to use them.
Trust and security
Flexboox publishes the controls it can support with current product and operational evidence—and leaves out certification badges and guarantees it cannot substantiate.
Access follows workspace roles
Sensitive operational actions remain traceable
Connected providers are named honestly
Security claims stay evidence-led
Current beta posture
Evidence snapshot
Workspace access
Role and permission checks
Tenant boundary
Workspace-scoped records
Support access
Purpose-bound and time-limited
Operational history
Traceable high-impact actions
No certification badge is implied by this product-control summary.
Current safeguards
The useful question is not whether a badge looks reassuring. It is who can do what, how sensitive actions are constrained, and whether the resulting activity can be reviewed.
Owner and staff permissions keep workspace, team, integration, and finance controls with the people expected to use them.
Workspace context is enforced across operational records so one business cannot browse another business’s bookings, customers, or configuration.
Important booking, payment, integration, support, and configuration activity is written to structured operational records.
Elevated platform access uses multifactor checks, explicit review, and privacy-aware operational views.
Support sessions require a documented purpose, recent authentication, a fixed expiry, and an audit record.
Configured Stripe or Mollie accounts handle payment collection while Flexboox keeps the booking and payment status connected.
Data responsibility
A business chooses its calendars, payment providers, communication services, and external destinations. Flexboox keeps those routes explicit and exposes their operational consequences during setup.
01
The booking page collects only the information needed for the configured booking path.
02
Availability, eligibility, booking state, and owner-visible history remain tenant-scoped.
03
Only enabled calendars, payments, communication services, or external destinations receive their required data.
Provider availability and exact data handling depend on the workspace configuration and the provider account selected by the business.
Evidence boundary
Current product controls
Roles, tenant-scoped access, audit records, limited support sessions, rate limits, payment-provider webhooks, and integration credential masking.
Operational evidence
Production-readiness checks, health routes, delivery ledgers, guarded webhook processing, and documented recovery actions.
Not currently claimed
No unverified certification, audit, hosting-region, uptime SLA, or absolute-security promise is presented as complete.
Need a buyer or security review?
Tell us what your organisation needs to evaluate, and we will answer from current evidence.
Evidence before badges
Start with the controls available today, then bring your buyer, privacy, or security questions to a focused review.