Security & data protection
Your compliance datais protected.
Documents are encrypted with AES-256 at rest and TLS 1.3 in transit, held under per-tenant isolation, and classified by an AI path with Anthropic Zero Data Retention enabled, so your files never train a model. What FileFlo is not yet certified for is on this page too, in the same size type.
AES-256 · TLS 1.3 · Per-tenant isolation · Anthropic Zero Data Retention
The floor
AES-256
At rest · TLS 1.3 in transit · Per-tenant isolation
ZDR
Anthropic Zero Data Retention
Documents never train models
Per-tenant
Data isolation
Scoped to your organization
Row-level
Postgres security on Supabase
Hosted on AWS, U.S. regions
What we do not claim
The badges we have not earned yet.
Compliance buyers get told what a vendor is certified for. This is the other half. If a badge is not on this list as issued, FileFlo does not have it, and we will say so in a questionnaire the same way we say it here.
FileFlo is not SOC 2 certified. The first Type II audit is targeted for Q4 2026 / Q1 2027. Architecture and policies are designed against SOC 2 controls; no certification has been issued.
FileFlo is not HIPAA-certified. The architecture is designed against HIPAA technical safeguards. BAAs become available on Professional plans at attestation completion, targeted Q1 2027.
FileFlo holds no GDPR audit attestation. Data portability, right to deletion, and access controls are designed against GDPR requirements; formal attestation is pending.
FileFlo is not ISO 27001 certified. That effort is planned for Q3 2027.
Your documents are never used to train AI models. Anthropic Zero Data Retention is enabled on the classification path.
FileFlo does not staff 24/7 support. Security and support questions are answered Monday to Friday, 8 a.m. to 6 p.m. Mountain Time.
The controls
Every control, named.
Six controls, stated plainly, including the two that are still a target date rather than a certificate.
256-Bit Encryption
All data is encrypted in transit (TLS 1.3) and at rest (AES-256) using industry-standard encryption protocols.
SOC 2 Type II (Planned Q4 2026)
First SOC 2 Type II audit targeted for Q4 2026 / Q1 2027. Architecture and policies designed against SOC 2 controls; formal certification not yet started.
HIPAA (Planned Q1 2027)
HIPAA-aware architecture: AES-256 encryption, role-based access, audit logs, tenant data isolation. Formal HIPAA certification and BAAs available upon Q1 2027 attestation completion.
Role-Based Access Control
Granular permissions ensure employees only see data relevant to their role and responsibilities.
Secure Infrastructure
Hosted on AWS with automatic backups and disaster recovery protocols.
GDPR-Aware Data Handling
Data portability, right to deletion, and access controls designed against GDPR requirements. Formal GDPR audit attestation pending.
How we operate
Five practices, running today.
Data Encryption
All data is encrypted at rest using AES-256 and in transit using TLS 1.3. We never store sensitive data in plain text.
Access Controls
Multi-factor authentication, SSO support, and role-based permissions ensure only authorized users can access data.
Data Backup
Automated daily backups with 30-day retention. Point-in-time recovery available for all customer data.
Monitoring
Automated threat detection and incident response protocols to protect customer data.
Compliance
We are building toward SOC 2 Type II and HIPAA. Today, we follow security best practices around data handling, access control, and audit logging.
Certification roadmap
Where each certification actually stands.
Target dates, not progress bars. None of the four below has been issued.
| Certification | Timeline | Status today |
|---|---|---|
| SOC 2 Type II | Planned Q4 2026 / Q1 2027 | In development. Not yet certified. |
| HIPAA | Planned Q1 2027 | Architecture designed against HIPAA technical safeguards. Not yet certified. |
| GDPR | Architecture in place | Formal audit attestation pending. |
| ISO 27001 | Planned Q3 2027 | Not started. |
Procurement summary
FileFlo security at a glance.
One-page snapshot for compliance officers, procurement, and IT reviewers. Forward this page or print it for your file.
- Encryption
- AES-256 at rest. TLS 1.3 in transit.
- Data isolation
- Per-tenant isolation; each customer's data is scoped to their organization.
- Access controls
- Role-based permissions, MFA, SSO support, audit logs of access and document actions.
- AI & data retention
- Anthropic Zero Data Retention (ZDR) is enabled. Customer documents are not used for model training.
- SOC 2
- Type II audit targeted Q4 2026 / Q1 2027. In development, not yet certified. Architecture and policies designed against SOC 2 controls.
- HIPAA
- Architecture designed against HIPAA technical safeguards. BAA available on Professional plans at attestation completion (target Q1 2027). Not yet HIPAA-certified.
- Backups
- Automated daily backups with 30-day retention. Point-in-time recovery available.
- Support hours
- Monday to Friday, 8 a.m. to 6 p.m. Mountain Time. Email: chad@getfileflo.com.
- Infrastructure
- Hosted on AWS in U.S. regions. Built on Supabase (Postgres) with row-level security.
- Sub-processors
- AWS (hosting), Supabase (database), Stripe (billing), Anthropic (AI classification, ZDR enabled). Full list on request.
Need a security questionnaire response, DPA, or sub-processor list? Email chad@getfileflo.com. We respond within one business day, Monday to Friday MT.
The technical detail // For IT & compliance reviewers
How FileFlo handles your data.
FileFlo encrypts all data at rest with AES-256 and in transit with TLS 1.3, and never stores sensitive data in plain text. Each customer's data is held under per-tenant isolation, scoped to their organization, and the platform is built on Supabase (Postgres) with row-level security and hosted on AWS in U.S. regions. Access is governed by role-based permissions with multi-factor authentication and SSO support, so employees only see data relevant to their role; access and document actions are recorded in audit logs.
For AI classification, FileFlo uses Anthropic with Zero Data Retention (ZDR) enabled, so customer documents are not used for model training. The platform's sub-processors are AWS (hosting), Supabase (database), Stripe (billing), and Anthropic (AI classification, ZDR enabled), with the full list available on request. Customer data is protected by automated daily backups with 30-day retention and point-in-time recovery, and by automated threat detection and incident response protocols.
On certifications, FileFlo is building toward SOC 2 Type II and HIPAA. The first SOC 2 Type II audit is targeted for Q4 2026 / Q1 2027 (in development and not yet certified), with architecture and policies designed against SOC 2 controls. The architecture is also designed against HIPAA technical safeguards, with formal HIPAA certification and BAAs (available on Professional plans) at attestation completion targeted for Q1 2027. Data handling is designed against GDPR requirements (data portability, right to deletion, and access controls), with formal GDPR audit attestation pending, and an ISO 27001 effort planned for Q3 2027. Support is available Monday to Friday, 8 a.m. to 6 p.m. Mountain Time at chad@getfileflo.com.
Security review
Have security questions?
We answer security questionnaires, provide detailed security documentation, and issue BAAs for healthcare organizations (available on Professional plans at HIPAA attestation completion). If the answer is "not yet," you will get that answer plainly.
Reply within one business day · Monday to Friday MT