> ## Documentation Index
> Fetch the complete documentation index at: https://docs.benefitflow.com/llms.txt
> Use this file to discover all available pages before exploring further.

# FlowPilot Security & Data Handling

> How FlowPilot protects your data, what it can access, and the controls available to your team.

FlowPilot is BenefitFlow's AI-powered assistant that helps you search, summarize, and draft content directly inside the platform. For a full walkthrough of capabilities, see [Getting Started with FlowPilot](/knowledge-base/getting-started-flowpilot).

This article covers how FlowPilot handles your data, the infrastructure behind it, and the controls available to your team's administrators.

***

## How FlowPilot Works

Every FlowPilot interaction follows the same data flow:

<Steps>
  <Step title="You ask a question">
    You type a question or request in the FlowPilot panel — for example, "Summarize this employer's benefits" or "Draft a prospecting email."
  </Step>

  <Step title="FlowPilot identifies intent">
    FlowPilot determines what type of request you made: a search, a summary, a draft, or a general question.
  </Step>

  <Step title="Relevant data is retrieved">
    FlowPilot pulls the data it needs from BenefitFlow's existing database — the same data already visible in your BenefitFlow account.
  </Step>

  <Step title="The AI model processes your request">
    Your query and the relevant context are sent to the AI model for processing (see [AI Infrastructure](#ai-infrastructure) below).
  </Step>

  <Step title="You receive a response">
    The response is returned to you in the FlowPilot panel.
  </Step>
</Steps>

<Warning>
  FlowPilot does **not** access external data, the internet, or any systems outside of BenefitFlow. Every response is grounded in data already available within the platform.
</Warning>

***

## AI Infrastructure

FlowPilot uses Anthropic's Claude language models, hosted on **AWS Bedrock** — Amazon's managed AI service. Here is what that means for your data:

| Concern                                 | How FlowPilot Addresses It                                                                                                                         |
| :-------------------------------------- | :------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Where is data processed?**            | All data is processed within BenefitFlow's AWS environment. Your data does not leave your cloud infrastructure to reach a third-party AI provider. |
| **Is my data used for model training?** | No. AWS Bedrock does not use customer data to train or improve AI models.                                                                          |
| **Is data shared with Anthropic?**      | No. Your queries, responses, and data are not shared with Anthropic or any other third party for model training or any other purpose.              |
| **How is quality monitored?**           | BenefitFlow uses internal observability tooling to monitor response quality and safety. This monitoring is entirely internal to BenefitFlow.       |

***

## What Data FlowPilot Can Access

FlowPilot can **only** access data that is already visible to you in your BenefitFlow account. It operates within the same permissions as the logged-in user.

**FlowPilot can access:**

* Employer profiles
* Broker profiles
* Contact records
* Benefits filings
* Search results
* Other data visible in your current BenefitFlow session

**FlowPilot cannot access:**

* Other customers' data (tenant isolation is enforced)
* Backend-only system data
* Data outside of BenefitFlow
* The internet or any external APIs

<Tip>
  FlowPilot saves your conversation history so you can revisit past chats from the FlowPilot history menu. Your history is private to you (teammates and admins can't see it) and is never used to train AI models.
</Tip>

***

## Admin Controls

Team administrators can manage FlowPilot access for their entire organization.

| Setting                      | Details                                                                                             |
| :--------------------------- | :-------------------------------------------------------------------------------------------------- |
| **Where to find it**         | [Team Management > Settings](https://benefit-flow.com/Team?tab=settings)                            |
| **What it controls**         | Enables or disables FlowPilot for all members of your team                                          |
| **When disabled**            | All FlowPilot entry points are completely hidden — your users will not see any trace of the feature |
| **When changes take effect** | Immediately, for all team members                                                                   |

<Frame>
  <img src="https://mintcdn.com/benefitflow/15n8c_aZt5sf8-U6/images/flowpilot-admin-toggle-enabled.png?fit=max&auto=format&n=15n8c_aZt5sf8-U6&q=85&s=27a1109f69bfdccc4457283b70c734a1" alt="FlowPilot toggle enabled in Team Management Settings" width="2108" height="1110" data-path="images/flowpilot-admin-toggle-enabled.png" />
</Frame>

<Frame>
  <img src="https://mintcdn.com/benefitflow/15n8c_aZt5sf8-U6/images/flowpilot-admin-toggle-disabled.png?fit=max&auto=format&n=15n8c_aZt5sf8-U6&q=85&s=e7acebc3fb7954189dad1b3ba08c2b0f" alt="FlowPilot toggle disabled in Team Management Settings" width="2108" height="1088" data-path="images/flowpilot-admin-toggle-disabled.png" />
</Frame>

***

## Safety Guardrails

FlowPilot includes multiple layers of protection to ensure safe, reliable responses:

* **Grounded in visible data** — FlowPilot only references data visible on the current page. It does not speculate or invent facts.
* **System prompt isolation** — Internal system prompts are stripped from all responses.
* **Prompt injection protection** — Attempts to manipulate FlowPilot through prompt injection are detected and rejected.
* **No professional advice** — FlowPilot does not provide financial, legal, or insurance advice.
* **Interaction logging** — All interactions are logged internally for quality monitoring and safety review.

***

## Frequently Asked Questions

<AccordionGroup>
  <Accordion title="Is my data used to train AI models?">
    No. AWS Bedrock does not use customer data for model training. Your queries and responses are not shared with Anthropic or any third party.
  </Accordion>

  <Accordion title="Can FlowPilot access data from other BenefitFlow customers?">
    No. FlowPilot operates within your team's data permissions. It can only access data visible to the logged-in user. Tenant isolation is enforced at the infrastructure level.
  </Accordion>

  <Accordion title="Can I disable FlowPilot for my team?">
    Yes. Any team admin can toggle FlowPilot off in **Team Management > Settings**. When disabled, FlowPilot is completely hidden from all team members.
  </Accordion>

  <Accordion title="Does FlowPilot store my conversations?">
    Yes. FlowPilot keeps your conversation history indefinitely so you can revisit past chats and pick up where you left off — find them in the FlowPilot history menu. Your history is **private to you** — teammates and admins can't see your conversations — and is **not** used to train AI models.
  </Accordion>

  <Accordion title="What AI model does FlowPilot use?">
    FlowPilot uses Anthropic's Claude models, hosted on AWS Bedrock within BenefitFlow's AWS infrastructure. Your data does not leave BenefitFlow's cloud environment.
  </Accordion>

  <Accordion title="Does FlowPilot have access to the internet?">
    No. FlowPilot only accesses data within BenefitFlow's platform. It cannot browse the web, access external APIs, or reach any systems outside of BenefitFlow.
  </Accordion>

  <Accordion title="Is FlowPilot included in my subscription?">
    Yes. FlowPilot is included for all BenefitFlow users at no additional cost.
  </Accordion>
</AccordionGroup>

***

## Related Resources

<CardGroup>
  <Card title="Getting Started with FlowPilot" icon="wand-magic-sparkles" href="/knowledge-base/getting-started-flowpilot" horizontal={true} />

  <Card title="Security & Privacy Overview" icon="shield-check" href="/knowledge-base/security-privacy" horizontal={true} />

  <Card title="Data Removal Requests" icon="circle-question" href="/knowledge-base/data-removal-request" horizontal={true} />
</CardGroup>

***

Have additional security questions? Reach out to your BenefitFlow Customer Success Manager or email [customerteam@benefit-flow.com](mailto:customerteam@benefit-flow.com).
