Best Practices for Building High-Security FlutterFlow Apps with Firebase

Best Practices

Hi everyone,
We’re currently upgrading our MVP — built using FlutterFlow and Firebase — into a production-grade app that meets healthcare-grade standards (think HIPAA-level security). Our current setup relies heavily on FlutterFlow’s default Create/Update Document actions, and we’re exploring how to introduce encryption and robust data protection without rewriting our flows from scratch.

📌 Key Discussion Points:

  • If your app uses FlutterFlow’s default Firestore actions, what’s the best path to integrate encryption without disrupting existing flows?

  • Have you tackled data security in a regulated domain like healthcare or finance using this stack?

  • What best practices exist for securing Firestore and Firebase Storage (e.g., encrypted payloads, signed URLs, audit logging)?

  • Is there anything in FlutterFlow’s roadmap around field.

4
1 reply