hiflo/Resources · Trust

How we earn the trust.

Customer data lives where you choose. Every action is logged. Every claim is auditable. We sign the boring things in writing.

SOC 2type ii · audited annually
RLSrow-level security · postgres
99.97%uptime · 12-month avg
01Certifications & frameworks

The signed documents.

01

SOC 2 Type II

Independent third-party audit, renewed annually. Evidence pack available under NDA.

auditor · prescient · 2025
02

ISO 27001

In flight — targeted Q4 2026. Pre-audit complete.

in-flight · q4 2026
03

POPIA

Protection of Personal Information Act — South African data residency, retention controls, DSAR in-product.

live · in-product
04

GDPR

EU residency · Frankfurt. DPA signed with every customer. Sub-processor list public.

live · in-product
05

UK GDPR

Aligned with ICO guidance. UK customers can opt for UK-only data residency on Enterprise.

live
06

CCPA

California-specific consumer privacy rights for US customers. In-product DSAR.

live
02How the boundaries work

Engineered, not promised.

01

Multi-tenant row-level security

Every row is scoped at the database — not the app layer. Postgres RLS policies, third-party pen-tested annually. Each tenant gets a per-tenant encryption key.

postgres · rls · pen-tested annually
02

Flo's tools are sandboxed

Flo can only call enabled tools, on records the asking employee can already see. Every call is logged with the user's identity, not Flo's. Per-tool circuit breakers.

scoped tool use · per-user · auditable
03

Zero-retention LLM

Customer prompts and responses are never used for training. Zero-retention API access with our LLM provider. Committed in writing in our DPA.

zero retention · contractual · dpa
04

Encryption end-to-end

TLS 1.3 in transit, AES-256 at rest. Per-tenant data encryption keys, rotated quarterly. HSM-backed. Application-level encryption on sensitive columns.

tls 1.3 · aes-256 · hsm
05

Continuous monitoring

Anomaly detection on access patterns, tool calls, and data exfiltration. Alerts to customer security teams on configurable thresholds. Customer-visible audit log.

live · per-tenant · webhooks
06

Subprocessor list, public

Every subprocessor we use, listed publicly. Customer notified 30 days before any change. Override available on Enterprise.

subprocessors.hiflo.io
03Data residency

Where your data lives.

Pick once, lock in. We don't move customer data across regions without explicit consent.

AWS · af-south-1
South Africa Cape Town
POPIA · BCEA · SARS
selectable
AWS · eu-central-1
European Union Frankfurt
GDPR · DPA
selectable
AWS · eu-west-2
United Kingdom London
UK GDPR · ICO
selectable
AWS · us-east-1
United States N. Virginia
CCPA · state laws
selectable
04By the numbers

Twelve-month reliability.

99.97%
uptime · 12-month
0
data breaches · ever
11min
support · median
24h
security · response sla

Trust by default.

Request our SOC 2 Type II report and DPA under NDA — usually delivered within an hour.