Skip to main content

Security & data protection

Your compliance datais protected.

Documents are encrypted with AES-256 at rest and TLS 1.3 in transit, held under per-tenant isolation, and classified by an AI path with Anthropic Zero Data Retention enabled, so your files never train a model. What FileFlo is not yet certified for is on this page too, in the same size type.

By Chad GriffithFounder & CEOReviewed June 4, 2026

AES-256 · TLS 1.3 · Per-tenant isolation · Anthropic Zero Data Retention

The floor

AES-256

At rest · TLS 1.3 in transit · Per-tenant isolation

ZDR

Anthropic Zero Data Retention

Documents never train models

Per-tenant

Data isolation

Scoped to your organization

Row-level

Postgres security on Supabase

Hosted on AWS, U.S. regions

What we do not claim

The badges we have not earned yet.

Compliance buyers get told what a vendor is certified for. This is the other half. If a badge is not on this list as issued, FileFlo does not have it, and we will say so in a questionnaire the same way we say it here.

  • FileFlo is not SOC 2 certified. The first Type II audit is targeted for Q4 2026 / Q1 2027. Architecture and policies are designed against SOC 2 controls; no certification has been issued.

  • FileFlo is not HIPAA-certified. The architecture is designed against HIPAA technical safeguards. BAAs become available on Professional plans at attestation completion, targeted Q1 2027.

  • FileFlo holds no GDPR audit attestation. Data portability, right to deletion, and access controls are designed against GDPR requirements; formal attestation is pending.

  • FileFlo is not ISO 27001 certified. That effort is planned for Q3 2027.

  • Your documents are never used to train AI models. Anthropic Zero Data Retention is enabled on the classification path.

  • FileFlo does not staff 24/7 support. Security and support questions are answered Monday to Friday, 8 a.m. to 6 p.m. Mountain Time.

The controls

Every control, named.

Six controls, stated plainly, including the two that are still a target date rather than a certificate.

256-Bit Encryption

All data is encrypted in transit (TLS 1.3) and at rest (AES-256) using industry-standard encryption protocols.

SOC 2 Type II (Planned Q4 2026)

First SOC 2 Type II audit targeted for Q4 2026 / Q1 2027. Architecture and policies designed against SOC 2 controls; formal certification not yet started.

HIPAA (Planned Q1 2027)

HIPAA-aware architecture: AES-256 encryption, role-based access, audit logs, tenant data isolation. Formal HIPAA certification and BAAs available upon Q1 2027 attestation completion.

Role-Based Access Control

Granular permissions ensure employees only see data relevant to their role and responsibilities.

Secure Infrastructure

Hosted on AWS with automatic backups and disaster recovery protocols.

GDPR-Aware Data Handling

Data portability, right to deletion, and access controls designed against GDPR requirements. Formal GDPR audit attestation pending.

How we operate

Five practices, running today.

  1. Data Encryption

    All data is encrypted at rest using AES-256 and in transit using TLS 1.3. We never store sensitive data in plain text.

  2. Access Controls

    Multi-factor authentication, SSO support, and role-based permissions ensure only authorized users can access data.

  3. Data Backup

    Automated daily backups with 30-day retention. Point-in-time recovery available for all customer data.

  4. Monitoring

    Automated threat detection and incident response protocols to protect customer data.

  5. Compliance

    We are building toward SOC 2 Type II and HIPAA. Today, we follow security best practices around data handling, access control, and audit logging.

Certification roadmap

Where each certification actually stands.

Target dates, not progress bars. None of the four below has been issued.

FileFlo certification status: SOC 2 Type II, HIPAA, GDPR, and ISO 27001, with target dates and current status. None is currently issued.
CertificationTimelineStatus today
SOC 2 Type IIPlanned Q4 2026 / Q1 2027In development. Not yet certified.
HIPAAPlanned Q1 2027Architecture designed against HIPAA technical safeguards. Not yet certified.
GDPRArchitecture in placeFormal audit attestation pending.
ISO 27001Planned Q3 2027Not started.

Procurement summary

FileFlo security at a glance.

One-page snapshot for compliance officers, procurement, and IT reviewers. Forward this page or print it for your file.

Encryption
AES-256 at rest. TLS 1.3 in transit.
Data isolation
Per-tenant isolation; each customer's data is scoped to their organization.
Access controls
Role-based permissions, MFA, SSO support, audit logs of access and document actions.
AI & data retention
Anthropic Zero Data Retention (ZDR) is enabled. Customer documents are not used for model training.
SOC 2
Type II audit targeted Q4 2026 / Q1 2027. In development, not yet certified. Architecture and policies designed against SOC 2 controls.
HIPAA
Architecture designed against HIPAA technical safeguards. BAA available on Professional plans at attestation completion (target Q1 2027). Not yet HIPAA-certified.
Backups
Automated daily backups with 30-day retention. Point-in-time recovery available.
Support hours
Monday to Friday, 8 a.m. to 6 p.m. Mountain Time. Email: chad@getfileflo.com.
Infrastructure
Hosted on AWS in U.S. regions. Built on Supabase (Postgres) with row-level security.
Sub-processors
AWS (hosting), Supabase (database), Stripe (billing), Anthropic (AI classification, ZDR enabled). Full list on request.

Need a security questionnaire response, DPA, or sub-processor list? Email chad@getfileflo.com. We respond within one business day, Monday to Friday MT.

The technical detail // For IT & compliance reviewers

How FileFlo handles your data.

FileFlo encrypts all data at rest with AES-256 and in transit with TLS 1.3, and never stores sensitive data in plain text. Each customer's data is held under per-tenant isolation, scoped to their organization, and the platform is built on Supabase (Postgres) with row-level security and hosted on AWS in U.S. regions. Access is governed by role-based permissions with multi-factor authentication and SSO support, so employees only see data relevant to their role; access and document actions are recorded in audit logs.

For AI classification, FileFlo uses Anthropic with Zero Data Retention (ZDR) enabled, so customer documents are not used for model training. The platform's sub-processors are AWS (hosting), Supabase (database), Stripe (billing), and Anthropic (AI classification, ZDR enabled), with the full list available on request. Customer data is protected by automated daily backups with 30-day retention and point-in-time recovery, and by automated threat detection and incident response protocols.

On certifications, FileFlo is building toward SOC 2 Type II and HIPAA. The first SOC 2 Type II audit is targeted for Q4 2026 / Q1 2027 (in development and not yet certified), with architecture and policies designed against SOC 2 controls. The architecture is also designed against HIPAA technical safeguards, with formal HIPAA certification and BAAs (available on Professional plans) at attestation completion targeted for Q1 2027. Data handling is designed against GDPR requirements (data portability, right to deletion, and access controls), with formal GDPR audit attestation pending, and an ISO 27001 effort planned for Q3 2027. Support is available Monday to Friday, 8 a.m. to 6 p.m. Mountain Time at chad@getfileflo.com.

Security review

Have security questions?

We answer security questionnaires, provide detailed security documentation, and issue BAAs for healthcare organizations (available on Professional plans at HIPAA attestation completion). If the answer is "not yet," you will get that answer plainly.

Reply within one business day · Monday to Friday MT