Floww for Scaling Companies
Floww enables scaling companies to raise private capital through a compliant, institution-grade infrastructure. Companies can present opportunities, onboard and manage investors, and communicate progress securely, retaining control over visibility and relationships while Floww handles regulatory governance and investor processes in the background.
Features
- Build interactive investor-ready deal pages with real-time updates.
- Control investor access with secure permission-based sharing.
- Track investor engagement and viewing behavior automatically.
- Capture investor interest directly for price discovery insights.
- Run compliant Q&A during your fundraise.
- Use built‑in KYC, KYB, and AML verification.
- Receive FCA‑regulated financial promotion reviews for investor trust.
- Manage allocations with orderbook technology.
- Execute legal documents and settlements end‑to‑end.
- Receive expert guidance throughout your fundraising process.
Benefits
- Present a polished, professional story to investors instantly.
- Understand investor appetite with real‑time analytics.
- Reduce risk with fully compliant onboarding and checks.
- Improve fundraise efficiency through seamless execution tools.
- Convert interest into commitments more confidently.
- Reduce friction with streamlined investor onboarding and verification
- Strengthen investor confidence through FCA‑regulated processes.
- Save time with expert-supported fundraising execution.
- Maintain full transparency of investor activity and engagement.
- Close rounds faster with seamless end‑to‑end tooling.
Pricing
- Free trial available
Service documents
Request an accessible format
Framework
G-Cloud 15
Service ID
9 4 4 7 9 9 0 4 6 2 9 7 5 4 4
Contact
Floww
Umerah Akram
Telephone: +44 20 4526 7912
Email: governmentfindatender@floww.io
About your service
- Service categories
-
Applications
Collaborative
- Enterprise community
- Multi cloud support
- No
Service scope
- Software add-on or extension
- No
- Cloud deployment model
- Public cloud
- Service constraints
- There are no constraints
- System requirements
-
- Dual Core 2Ghz or faster CPU
- 4GB RAM
- 1920 x 1080 Resolution Recommended
- 2Mbit Internet or faster
- Up to date OS ether MAC or Windows
- Either Chrome, Firefox, Sarfari or Edge ( Latest version Recommended)
- IPhone running latest IOS
User support
- Email or online ticketing support
- Yes
- Support response times
-
All of our user support emails are manned during UK working hours. Outside of hours and on weekends they are not, but an auto-response is always triggered. Regardless, our protocol is to Respond and Resolve within the below timeframes (including only 'working day' hours - i.e. if I message is received at 10pm the response window clock will begin 8:30am the following day) 4 hour Response
8 hour Resolution" - User can manage status and priority of support tickets
- No
- Phone support
- No
- Web chat support
- Yes
- Web chat support availability
- 9 to 5 (UK time), Monday to Friday
- Web chat support accessibility standard
- None or don’t know
- How the web chat support is accessible
- The webchat within the Floww platform is provided by Hubspot who commit to meeting or exceeding WCAG2.1 AA standards. Its supports assistive technologies such as screen readers and high-contrast modes.
- Web chat accessibility testing
- We have not carried out any web chat testing as of yet.
- Onsite support
- No
- Support levels
-
1. We provide buyers email and telephone support via our customer support desk
2. We offer buyers a number of support packages that deliver various levels of support. Support is provided for both the platform and business process related issues such as data ingestion.
3. When necessary we can provide direct access to our technical teams via our documented escalation process.
We do not charge for support. - Support available to third parties
- No
- AI chatbot
- No
Onboarding and offboarding
- Getting started
-
Following self-signup, an account manager will communicate with the buyer via email, video call, or both, to (a) get an understanding of the buyer's needs, and (b) assist in onboarding the platform, and (c) demo best use of the platform features.
Buyers can also request the help of an account manager prior to signup, in order to get an understanding of the onboarding process and platform features.
The account manager will assist the buyer in building out their environment within the platform, and liaise with the broader team where data is to be ingested internally and then presented within the buyer's environment.
Floww's Help Centre also contains numerous articles covering FAQ's and guidance. - Service documentation
- Yes
- Documentation formats
-
- HTML
- End-of-contract data extraction
-
At the end of the contract the buyer’s account will be deleted. Floww support will work with the buyer if necessary to extract/export the data from the platform prior to deletion.
Please contact us for further details on this process. - End-of-contract process
- Buyers must cancel their subscription via email within 30 days prior to the end of the subscription period. Once the paid subscription is cancelled users will still have access to the free features. Information on what features are included with each subscription tier is available on our website.
- Documentation accessibility standard
- None or don’t know
- How the documentation is accessible
-
Floww's Help Centre contains guidance on how a buyer can onboard and what they can expect during the onboarding process.
Should a buyer wish to offboard, (a) they can contact an account manager directly, (b) submit an offboarding request via email or online chat.
Floww's Help Centre also contains guidance in support of point (2).
Using the service
- Web browser interface
- Yes
- Supported browsers
-
- Microsoft Edge
- Firefox
- Chrome
- Safari
- Application to install
- No
- Designed for use on mobile devices
- Yes
- Differences between the mobile and desktop service
- The service has been designed to work effectively on mobile devices as well as desktop. A dedicated iOS native app is also provided, focused on portfolio and performance monitoring and secure sharing of deal information. To deliver an optimal user experience, the iOS app leverages native platform capabilities such as built-in sharing tools and native charting libraries for investment performance visualisation. Editing features are intentionally limited on mobile. The desktop web application is fully responsive and adapts for use on mobile browsers, including non-iOS platforms.
- Service interface
- Yes
- User support accessibility
- None or don’t know
- Description of service interface
- Access to the service is available via our web-based interface, in which we apply standard browser controls, with a fully responsive intuitive user experience, allowing users to interact freely with the features available to them. This includes the ability to upload their own files and data to the platform, as well as being able to sort and filter views and export data in certain view types. Configuration of the system can be performed in this interface too.
- Accessibility standards
- None or don’t know
- Description of accessibility
- Users can access all features via the browser and all content is optimised for readability, predictability and to provide appropriate input assistance and error prevention when collecting and processing any user-submitted data.
- Accessibility testing
- No assistive testing is carried out at present.
- API
- No
- Customisation available
- Yes
- Description of customisation
- As we are a multi-tenanted platform and there is some level of customisation available, in addition buyers can also brand specific areas of their profile on the platform, such as the addition of a company logo and banner image.
Scaling
- Independence of resources
-
The Floww platform is built using highly scalable application microservices and is designed from the ground up to scale out on demand as load increases.
An individual user on the platform will have no impact to other users of the platform as the platform is designed to always have available capacity and to autoscale if capacity reaches a defined threshold.
Analytics
- Service usage metrics
- No
Resellers
- Supplier type
- Not a reseller
Staff security
- Staff security clearance
- Other security clearance
- Government security clearance
- None
Asset protection
- Knowledge of data storage and processing locations
- Yes
- Data storage and processing locations
-
- United Kingdom
- European Economic Area (EEA)
- User control over data storage and processing locations
- No
- Datacentre security standards
- Complies with a recognised standard (for example CSA CCM version 4.0)
- Penetration testing frequency
- At least once a year
- Penetration testing approach
- NCSC approved service provider
- Protecting data at rest
-
- Physical access control, complying with SSAE-18 / ISAE 3402
- Physical access control, complying with another standard
- Encryption of all physical media
- Scale, obfuscating techniques, or data storage sharding
- Data sanitisation process
- Yes
- Equipment disposal approach
- Complying with a recognised standard, for example CSA CCM v4.0, CAS (Sanitisation) or ISO/IEC 27001
- Data sanitisation type
-
- Deleted data can’t be directly accessed / Cryptographic Erasure
- Data Erasure
Data importing and exporting
- Data export approach
-
All transaction data can be exported in platform. Buyers will need to contact the Floww support desk to organise the export of their portfolio data. Once a support ticket has been raised Floww will work with the buyer to securely export their data within an agreed period of time.
Further details on this process can be provided. - Data export formats
-
- CSV
- Other
- Other data export formats
-
- Word
- Excel
- Powerpoint
- Data import formats
-
- CSV
- Other
- Other data import formats
-
- Excel
- Word
- Powerpoint
Data-in-transit protection
- Data protection between buyer and supplier networks
- TLS (version 1.2 or above)
- Data protection within supplier network
- TLS (version 1.2 or above)
Availability and resilience
- Guaranteed availability
-
Floww does not offer a service level agreement however the platform has been designed to provide 99.9% availability. This availability is achieved by using the latest resilient microservices application architecture and other clustering and high availability technologies.
The infrastructure has been designed to survive the loss of a single component or an entire data centre/region. - Approach to resilience
- The Floww platform is hosted in Microsoft Azure across two regions. All services are duplicated within a region and are active/passive across multiple regions. This design provides both intra and inter regional high availablity. Further details can be provided on request.
- Outage reporting
-
Floww will report all service outages via its in house support desk. The ITSM function is aligned to ITIL's support framework and will manage and own any incident/problem through to final resolution.
If neccessary users will be informed of a service interruptions via an initial email, further email updates will be provided as part of Flowws incident/problem management process. Root cause analysis will be provided as part of the post incident report.
Service maintenance will be scheduled in advance with as much noticed as possible, and all work will be completed out of hours.
Identity and authentication
- User authentication needed
- Yes
- User authentication
-
- Multi-Factor Authentication (MFA)
- Username or password
- Access restrictions in management interfaces and support channels
-
Access to support and managment channels are restricted to specific individuals. Floww adheres to the principles of least privilege access and where possible access is only provided for a specific period of time (Point in time access). Role based access and MFA is used to restrict access to all services and resources.
All managment interfaces are accessed across secure TLS or secure Zero Trust VPN tunnels. All critical resources have Identity Access Managment auditing enabled for logging purposes. - Access restriction testing frequency
- At least once a year
- Management access authentication
-
- Multi-Factor Authentication (MFA)
- Identity federation with existing provider (for example Google Apps)
- Dedicated link (for example VPN)
- Username or password
Audit information for users
- Access to user activity audit information
- Users contact the support team to get audit information
- How long user audit data is stored for
- At least 12 months
- Access to supplier activity audit information
- Users contact the support team to get audit information
- How long supplier audit data is stored for
- At least 12 months
- How long system logs are stored for
- At least 12 months
Security governance
- Named board-level person responsible for service security
- Yes
- Security governance certified
- Yes
- Security governance standards
- ISO/IEC 27001
- Information security policies and processes
-
Floww operates an Information Security Management System (ISMS) that is fully certified to ISO/IEC 27001. Our information security policies and processes are governed, maintained, and audited in line with this standard.
Our ISMS includes policies covering
• Information Security Policy
• Access Control
• Asset Management
• Cryptographic Controls
• Secure Development and Change Management
• Logging and Monitoring
• Vulnerability Management
• Supplier and Third Party Risk Management
• Incident Management and Reporting
• Business Continuity and Disaster Recovery
• HR Security (onboarding, screening, training, offboarding)
Reporting structure
Information security is overseen by the Head of Security, who reports directly into senior leadership.
How we ensure policies are followed
• All employees undergo mandatory annual security training and policy acknowledgement.
• Regular internal audits are conducted as part of the ISO 27001 ISMS audit cycle.
• Risks, incidents, and non conformities are logged and tracked through a formal process with defined escalation routes.
• Technical controls such as MFA, least privilege access, secure configuration baselines, vulnerability scanning, and continuous monitoring are enforced across our environment.
• External accredited ISO 27001 auditors conduct annual surveillance audits to validate compliance.
Floww’s ISMS ensures consistent, auditable, and robust information security practices. - Software Security Code of Practice
- Yes
Operational security
- Configuration and change management standard
- Supplier-defined controls
- Configuration and change management approach
-
All changes to Flowws services are assessed for business impact/risk, security risk and operational resilience. A change must pass through change control where it is vetted by members of the change advisory team. If authorised, then the change is completed, and any relevant service design documentation is updated to reflect the new state.
All changes are reviewed against the current security posture of services to determine the impact of the change and any change to the overall risk profile of the business. Any that are of significant impact will be authorised by the CTO and Head of Security. - Vulnerability management type
- Supplier-defined controls
- Vulnerability management approach
- Flowws vulnerability management approach is focused on maintaining both an affective security posture and the cyber-resilience of the company. Floww makes use of security tools provided by Microsoft and other security vendors to regularly scan, report and remediate on potential security threats across the infrastructure. Code is also regularly reviewed and scanned for weaknesses and vulnerabilities. If a incident is detected then IT Teams will follow a documented incident response process to contain/remove any threat whilst maintaining effective communication channel with our clients.
- Protective monitoring type
- Supplier-defined controls
- Protective monitoring approach
- All alerts and security events are configured to send an email alert when triggered. Alerts are fed into our Incident management process and immediately investigated and escalated up to the CTO if required. In addition, Microsoft security centre and other security services provide centralized dashboards to determine Flowws current security posture and visualise any threats or suspicious events that may have occurred. Internet facing firewalls are configured with IPS and Advanced Malware protection services that monitors/alerts/blocks threats. Web application firewalls and Content Security Headers are also implemented as further layers of security.
- Incident management type
- Complies with a recognised standard, for example, CSA CCM v4.0 or ISO/IEC 27035:2011 or SSAE-18 / ISAE 3402
- Incident management approach
-
Floww operates a formal incident management process aligned with ISO 27001:2022. We maintain predefined procedures for common events, including security incidents, service disruptions, data issues, and access problems. Incidents follow structured triage, severity assessment, containment, investigation, resolution, and post‑incident review.
Users report incidents through our service desk via email or ticketing, while staff follow internal ISO 27001 reporting and escalation routes to the Head of Security.
For major or security‑related incidents, Floww provides customers with timely updates and a full incident report detailing impact, root cause, actions taken, and corrective improvements to prevent recurrence. - Post-quantum cryptography secure
- Yes
Secure development
- Approach to secure software development best practice
- Independent review of processes (for example CESG CPA Build Standard, ISO/IEC 27034, ISO/IEC 27001 or CSA CCM v4.0)
Public sector networks
- Connection to public sector networks
- No
Pricing
- Discount for educational organisations
- No
- Free trial available
- Yes
- Description of free trial
- A 30 day fully featured trial can be arranged.
Discount percentage by annual call-off contract value (excluding VAT)
- Less than £250,000
- 5%
- Between £250,000 and £500,000
- 5%
- Between £500,001 and £1,000,000
- 5%
- Between £1,000,001 and £2,500,000
- 5%
- Between £2,500,001 and £5,000,000
- 5%
- Over £5,000,001
- 5%
Non-mandatory Standards and certifications
- ISO/IEC 27001 certification
- Yes
- Who accredited the ISO/IEC 27001
- UKAS
- ISO/IEC 27001 accreditation date
- Tuesday 14 December 2021
- What the ISO/IEC 27001 doesn’t cover
- All parts of the organisation and all the services are in scope to the ISO certification.
- ISO 28000:2022 certification
- No
- ISO 9001 certification
- No
- Quality management systems (QMS)
- No
- CSA STAR certification
- No
- PCI certification
- No
- Cyber essentials
- No
- Cyber Essentials Alternative
- In relation to the services you do not have a current and valid Cyber Essentials certificate which has been awarded by one of the government approved Cyber Essentials accreditation bodies but you are working towards gaining it, and will be in a position to confirm that you have been awarded a current and valid Cyber Essentials certificate by one of the government approved accreditation bodies within 12 months of the date of award.
- Cyber essentials plus
- No
- Cyber Essentials Alternative
- None of the criteria
- Other security certifications
- Yes
- Any other security certifications
-
- ISO27017
- ISO27018
Social value
- Section B - Commitment for Future: Delivery
-
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 1: Fair work: That offers fair wages and good working conditions. Help people get a job, stay in work, and progress in their careers, with good employment opportunities across the country. Notes: Where there is a large proportion of labour costs in the contract, commercial teams should consider MAC in Outcome 1 as a priority
- New or retained jobs on the contract workforce in the relevant area that meet the criteria set out in MAC 1b, 1c and 1d
- Providing opportunities for, and measuring and monitoring of, staff workforce conditions over time, including employee engagement, involvement in decision-making and satisfaction and adapting to any changes in the results, with clear processes for acting on issues identified
-
Mission: Kick start economic growth. To secure the highest sustained growth in the G7 - with good jobs and productivity growth in every part of the country making everyone, not just a few, better off.
Policy Outcome 3: Resilient, innovative and flexible supply chains: Support economic growth through enabling resilient businesses, opportunities for small businesses and voluntary, community and social enterprises
- Understanding of the types of businesses in the market and the level of participation by new businesses, entrepreneurs, start-ups, SMEs, VCSEs and mutuals
-
Mission: Break down barriers to opportunity: By reforming our childcare and education systems, to make sure there is no class ceiling on the ambitions of young people in Britain
Policy Outcome 6: Employment and training: For those who face barriers to employment
- Understanding of the issues affecting the representation of disabled people in the workforce in the market, industry or sector relevant to the contract, and in the supplier’s own organisation and those of its key sub-contractors
- Working conditions which promote an inclusive working environment and promote retention and progression
-