Mindflow logo
Workflow Automation · Agents Orchestration Frameworks

Mindflow

Mindflow is a no-code hyperautomation and orchestration platform for enterprise IT, SecOps and CloudOps teams. It pairs a drag-and-drop workflow engine with autonomous AI agents that reason and act across 4,000+ integrations and 150,000 operations.

Active GDPR compliant Free plan · Free trial Contact Sales No public API Verified by Guidaio
Overview

What is Mindflow?

Mindflow is a GenAI hyperautomation and orchestration platform built for enterprise IT and cybersecurity teams: SecOps, ITOps, CloudOps, AIOps and managed security service providers. It brings two things together in a single interface, a no-code automation engine where workflows are assembled by drag and drop, and autonomous AI agents that reason, decide and act on their own.

What sets the platform apart is the breadth of what it can reach. Mindflow advertises a catalogue of more than 4,000 integrations and 150,000 operations, with full coverage of each connected service's API calls, alongside 450 ready-made templates. The homepage counter claims 316,495 hours of work saved across 1,582,478 playbook runs.

The product distinguishes three levels of autonomy. Predictive Workflows follow static rules and clearly defined tasks. AI Workflows combine language models with rule-based logic built on their structured outputs. Agentic AI goes further: you give an agent a mission, boundaries and scoped permissions, and it builds its own logic, adapts to shifting context and executes. Those agents run on a proprietary Large Action Model backed by OpenAI, Anthropic, Mistral and other vendors, and proprietary communication protocols let fleets of agents work in parallel or in sequence on one problem.

Getting something running does not require code. A text-to-automation feature turns a written prompt into working steps, and can even generate a tailored workspace, while contextual documentation for third-party APIs sits inside the editor rather than in another browser tab.

Governance is treated as a first-class concern: role-based access control on workspaces, scoped credentials held in an encrypted vault, action whitelists, human approval steps that can be inserted anywhere, and end-to-end auditing of prompts, decisions and API calls. A Relay Agent built on Cloudflare Zero Trust bridges the cloud platform to on-premises tools.

The publisher is a Paris company. The platform is deployed single-tenant on AWS serverless infrastructure, encrypts data with AES-256 at rest and in transit, and holds SOC 2 Type I and Type II audits together with ISO/IEC 27001 certification. A three-level certification programme rounds out the offer for teams building in-house expertise.

What it does

  • Describe a use case in plain language and let the AI assemble the flow steps for you
  • Deploy autonomous AI agents with a mission, a scope and explicit authorisations
  • Connect more than 4,000 third-party tools and call over 150,000 API operations
  • Build and edit no-code workflows on a drag-and-drop canvas
  • Trigger runs manually, on a schedule, on a recurrence, by webhook or by email
  • Route any step or task to a human for approval before it executes
  • Audit every run end to end, from step logs to prompts, decisions and API calls
Audience

When to use Mindflow / When not to

A quick filter to help you decide if Mindflow is the right fit.

When to use Mindflow

  • SOC and CSIRT teams automating alert triage, IOC enrichment and incident response
  • ITOps and CloudOps engineers handling offboarding, asset compliance and cloud clean-up at scale
  • Managed security service providers industrialising playbooks across several client environments
  • Organisations running a wide, heterogeneous tool stack that needs to be wired together
  • IT and security teams with no in-house developer, thanks to drag-and-drop building and prompt-to-flow generation

When not to use Mindflow

  • Buyers who need a published price before they commit: nothing is listed and every quote goes through a sales conversation
  • Anyone expecting a mobile or browser-extension experience, since Mindflow ships as a web application only
  • Developers hunting for a documented public API and SDK to embed the platform in their own product
  • Consumers and hobbyists, as the service is contracted for professional business use and is not directed to children
  • Teams that need guaranteed uptime without paying, because the 99.95% monthly SLA covers paid subscriptions only
Get started

How to use Mindflow

A typical end-to-end flow, from setup to results.

  1. Create an account from the sign-up page, or book a demo with an expert if you want a guided introduction
  2. Start from one of the 450 ready-made templates, or describe your use case in plain language and let text-to-automation lay down the steps
  3. Connect the services you need from the catalogue of more than 4,000 integrations
  4. Store the credentials for those services in the encrypted vault rather than in the flow itself
  5. Assemble the business logic on the canvas, transforming and extracting data with no-code functions
  6. Drop in a custom script through the low-code step when a case falls outside the available operations
  7. Break long processes into reusable sub-flows, version them, and document them with AI Note
  8. Choose how the flow fires: manually, on a schedule, on a recurrence, by webhook or by email
  9. Set the guardrails before going live, with workspace RBAC, action whitelists and human approval steps
  10. Watch it run through per-step logs and the reporting dashboard, and reach on-premises tools via the Relay Agent
Quick read

Pros & Cons

Pros

  • An unusually large integration catalogue, 4,000+ connectors with full coverage of their API calls, which is the platform's main edge over legacy SOAR tools
  • Genuinely accessible to non-developers, with drag-and-drop building, 450 templates and flow generation from a prompt
  • Covers the whole spectrum from deterministic workflows to AI-assisted flows and fully autonomous agents
  • Serious guardrails for agentic execution: granular RBAC, scoped credentials, action whitelists, human approval and end-to-end audit
  • SOC 2 Type I and Type II audits plus ISO/IEC 27001 certification, with a published DPA that names its subprocessors
  • Data hosted on AWS in Germany and Ireland by default, with a contractual commitment not to train models on customer data
  • A free Community Edition and a public 99.95% monthly SLA with tiered service credits on paid plans

Cons

  • No public pricing whatsoever: there is no pricing page and every figure is referred to the Order Form
  • Paid subscriptions carry an initial twelve-month commitment
  • The SLA, service credits and committed response times exclude the free, trial and Community Editions
  • AI Credits do not roll over from one month to the next, and AI executions can be blocked once the continuity buffer is exhausted
  • No documented public product API, no mobile app and no browser extension
  • No comparison or alternatives page, so positioning against competitors requires a sales conversation
  • The site is English-only and publishes no list of interface languages for the product itself
Pricing

Pricing & Plans

Mindflow does provide a free entry point: a Community Edition that runs until the customer terminates it, alongside trial accounts and open self-service sign-up. No paid price point is published. The site carries no pricing page at all, and the terms and conditions refer subscription fees and other charges to the applicable Order Form, so neither the lowest paid tier nor its currency can be stated. Paid subscriptions run for an initial term of twelve months, and the invoice may also include AI Credits, additional credit blocks, overage charges beyond the continuity buffer, and quoted Add-On Services.

Plan 1
Community Edition
  • free
  • runs until terminated by the customer
  • excluded from the SLA and from committed support response times
Plan 3
Paid Subscription
  • priced through an Order Form
  • initial term of twelve months
  • covered by the 99.95% monthly availability commitment and tiered service credits
Support tier Standard - included with paid subscriptions, response times measured in business hours (9
  • 00 to 18:00 CET/CEST
  • Monday to Friday)
Plan 5
Support tier Premium
  • faster committed response times than Standard across every severity level
Plan 6
Add-On Services
  • additional modules and capabilities quoted separately by Mindflow
Plan 7
AI Credits
  • included in the plan and purchasable in extra blocks
  • consumed per AI execution
  • monthly allocation not carried over
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Mindflow handles your data.

GDPR overview

Compliance is claimed in plain words: the security page states that Mindflow is committed to GDPR compliance. The controller is named, Mindflow, a societe par actions simplifiee registered in Paris under number 893 124 511 at 128 rue La Boetie, and a Data Protection Officer is designated at privacy@mindflow.io. The privacy policy, effective 16 January 2023 and last updated 1 July 2026, sets out access, rectification, erasure, restriction, objection, withdrawal of consent, portability, post-mortem instructions under French law and the right to complain to the CNIL. A Data Processing Agreement is published with a named subprocessor annex, general authorisation and thirty days' notice on any change. The company is established in the EEA; transfers beyond it rely on adequacy decisions, the EU-US Data Privacy Framework or Standard Contractual Clauses. No Article 27 representative is designated, and none is required.

Who owns the data?

Mindflow's terms leave little ambiguity. Customer data is and remains the exclusive property of the customer, who alone carries responsibility for it and for the right to use it. For the duration of the contract the customer grants Mindflow a limited, non-exclusive licence to host, reproduce, process and use that data, directly or through the subprocessors named in Annex 1 of the Data Processing Agreement, and solely to deliver, maintain, secure and support the service under documented instructions. Mindflow commits never to sell, rent or lease customer data. The publisher keeps the intellectual property of the platform, its connectors, generic components and templates, while the customer keeps its own configuration logic.

Reuse rights

The customer keeps its rights over AI inputs, meaning the prompts, instructions and content it submits, and may use the AI outputs for its own business purposes without asking Mindflow for permission, subject to applicable law, third-party rights and the terms of the AI provider involved. Workflows can be exported throughout the subscription in a structured, machine-readable JSON format covering flow logic, API steps, data transformation steps and non-sensitive metadata, although credentials, execution payloads, files, logs and audit records are deliberately left out. On its own side, Mindflow may only process the data to run, secure and support the service. It states that it does not train AI models in-house on customer data, and that no general-purpose model is trained or fine-tuned on it unless the customer opts in in writing. Where the customer connects its own AI account or API key, that provider's terms and retention settings apply instead.

Data retention & training

Retention summary
Under the Data Processing Agreement, user account data is kept for the life of the active account and up to 90 days after it closes; data processed to deliver the service and support records follow the same 90-day rule after the contract ends. At the end of the service the customer chooses whether Mindflow deletes or returns the personal data, and existing copies are deleted unless EU law requires otherwise. For data Mindflow controls itself, the privacy policy sets separate periods: up to three years after the last meaningful contact for commercial enquiries, support and marketing, around 24 months after an account ends, six to twelve months for security and connection logs, and ten years for invoices. After termination you keep at least 30 days to retrieve your data. Automatic backups are taken daily and retained for 35 days.
Trains on customer data
No
Training opt-out available
Yes
Subprocessors disclosed
Yes
DPA available
Yes
GDPR contact

Hosting summary

Mindflow declares itself established in the European Economic Area, and its published Data Processing Agreement names each subprocessor. Hosting and cloud infrastructure are provided by Amazon Web Services EMEA SARL, based in Luxembourg, with data located in Germany and Ireland unless the Order Form states otherwise. AI inference runs through Amazon Bedrock in the AWS region selected for the service, and through OpenAI Ireland when the customer picks an OpenAI model on a Mindflow-managed account. Customer support is handled by Intercom, which processes data in the United States and elsewhere under the EU-US Data Privacy Framework, with Standard Contractual Clauses as a fallback. The website itself is a separate matter: it is published and hosted through Framer B.V. in Amsterdam, and Mindflow explicitly does not represent that all website data stays exclusively in the European Union. The infrastructure runs on AWS serverless components, replicated across several data centres, with a documented recovery plan on alternate sites.

Hosting countries
🇩🇩 Germany🇮🇪 Ireland
Hosting regions
EU
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Mindflow.

  • Agents act on live third-party systems, and the customer stays responsible for the access scope, credentials, permissions and approval mechanisms it configures
  • Mindflow warns that AI outputs are probabilistic, non-deterministic and may be incomplete or inaccurate, so critical steps still need human judgement
  • Automating away routine investigation can erode the hands-on skills junior analysts build by doing that work themselves
  • Budget exposure is hard to predict without a public price list, and an initial twelve-month commitment leaves little room to change course
  • AI Credits do not roll over, overages are charged, and AI executions may be blocked once the continuity buffer is exhausted, which can interrupt live workflows
  • Support runs through Intercom in the United States, so support conversations may leave the EEA even though the platform data does not
  • Connecting your own AI provider account moves that processing outside Mindflow's DPA and under the provider's own retention terms
Setup

Setup & Integrations

Technical difficulty

Moderate, and front-loaded on your environment rather than on the tool. Building flows needs no code: drag and drop, 450 templates, generation from a prompt, and third-party API documentation shown in the editor. The real work is connecting your stack, supplying credentials to the encrypted vault, and setting the access scope, RBAC and approval steps. On-premises access requires deploying the Relay Agent, and the low-code step means a technical profile remains useful for edge cases. A demo with an expert and a three-level certification programme are available to shorten the ramp-up.

Deployment

Web app

Integrations

Slack Jira ServiceNow PagerDuty Zendesk GitHub Airtable VirusTotal Urlscan.io AbuseIPDB Have I Been Pwned GreyNoise Shodan URLhaus Hybrid Analysis TheHive CrowdStrike SentinelOne Sophos HarfangLab Jamf Pro Kandji Okta Google Admin Directory Microsoft Graph Splunk Datadog Sumo Logic Rapid7 InsightVM Tenable Wiz Lacework Netskope Zscaler Fortinet Trend Micro Vectra WALLIX Drata Amazon EC2 Amazon S3 AWS CloudTrail AWS Config Amazon Bedrock OpenAI Anthropic Mistral AI Databricks Ansible Galaxy Cloudflare Zero Trust IPinfo
Company

Behind Mindflow

Company name
Mindflow
Founded
21/10/2021
Country of origin
🇫🇷 France
Headquarters
128 Rue la Boetie, 75008 Paris, France
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇫🇷 France
Legal contact
Support contact

Fundraising

Seed round of EUR 5 million announced in March 2024, led by Auriga Cyber Ventures, Nauta Capital and Thales, with participation from Olivier Pomel, co-founder of Datadog (amount and date reported by the specialist press, not by the company website)
The company page names its backers without figures: Olivier Pomel (CEO of Datadog), Nauta Capital, Auriga Cyber Ventures and Thales Corporate Venture

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What exactly does Mindflow do?
It is a GenAI hyperautomation and orchestration platform for enterprise IT and cybersecurity teams. A no-code engine lets you build workflows by drag and drop, and autonomous AI agents can be given a mission, a scope and permissions to reason and act across a catalogue of more than 4,000 integrations and 150,000 operations.
Do I need to know how to code?
No. Flows are built on a drag-and-drop canvas, 450 templates are available, and a text-to-automation feature turns a written description into working steps. A low-code step is there for edge cases, so a technical profile remains useful, but it is not the entry ticket.
How much does it cost?
No price is published. There is no pricing page on the site, and the terms refer subscription fees to the applicable Order Form, which means going through a demo and a sales conversation. A free Community Edition exists and runs until you terminate it, and self-service sign-up is open.
Does it work with on-premises infrastructure?
Yes. A Relay Agent built on Cloudflare Zero Trust bridges the cloud platform and on-premises environments so Mindflow can reach tools that are not exposed to the internet.
Is my data used to train AI models?
No. Mindflow states that it does not train AI models in-house on customer data, AI inputs, AI outputs or customer configurations, and that it will not use them to train or fine-tune a general-purpose model unless the customer expressly opts in in writing. If you connect your own AI account or API key, that provider's terms apply instead.
Where is the data hosted?
On Amazon Web Services, in Germany and Ireland unless the Order Form states otherwise. Mindflow declares itself established in the EEA. Support is handled through Intercom, which processes data in the United States under the EU-US Data Privacy Framework with Standard Contractual Clauses as a fallback.
What security certifications does Mindflow hold?
The company reports successful SOC 2 Type I and Type II audits covering security, confidentiality, integrity and availability, and certified compliance with ISO/IEC 27001. The platform is deployed single-tenant, encrypts data with AES-256 at rest and in transit, and takes daily backups retained for 35 days.
How do I keep control of autonomous agents?
Each agent is bounded by its mission and scope. Granular role-based access control, scoped credentials, action whitelists and human approval steps on any task frame what it may do, and every action, prompt, decision and API call is auditable end to end.
Can I get my data out if I leave?
Yes. Workflows can be exported during the subscription in structured JSON covering flow logic, API steps, transformations and non-sensitive metadata. After expiry or termination you have a reasonable period of no less than thirty days to retrieve available data and exportable configurations, after which Mindflow may delete them under its retention policies.
Is there any training available?
Yes, a certification programme with three levels: Orchestrator for building automation playbooks, Solution Expert aimed at partners who present and sell the platform, and Professional Trainer for those becoming in-house experts.
Conclusion

Should you pick Mindflow?

Mindflow knows exactly who it is for, and that focus is its strength. This is not a general-purpose automation tool competing on breadth of audience; it is an orchestration platform for enterprise IT and cybersecurity operations, and almost every design decision reflects that. The integration catalogue, 4,000-plus connectors with full coverage of their API calls, is the single most convincing argument on the site, because it is precisely where legacy SOAR platforms tend to run out of road. Layering a no-code canvas and prompt-driven flow generation on top of that catalogue makes the platform reachable by people who would never write a script.

The governance story is unusually mature for an agentic product. Scoped credentials, action whitelists, human approval steps and end-to-end audit are the controls a security team will ask about first, and they are documented rather than implied. SOC 2 Type I and Type II, ISO/IEC 27001, a published DPA naming its subprocessors, EU hosting on AWS in Germany and Ireland, and a contractual promise not to train on customer data make the compliance conversation short.

The obvious friction is commercial. Nothing is priced publicly, every quote runs through an Order Form, and paid subscriptions start with a twelve-month commitment, which is a lot to ask before you know what you are spending. The free Community Edition softens that, and is the sensible way to judge the product without talking to anyone, provided you accept that it comes with no availability guarantee. Teams evaluating Mindflow should also weigh the AI Credit model, since allocations do not roll over and executions can be blocked once the buffer runs out. Worth a serious look if you are automating IT or security operations at scale; less so if you need a price on a page.