FloKit.AI is built so growth teams can move fast without giving up control of their data. Here are the frameworks we align to, the controls we run, and how to get what your security review needs.
The core controls behind every FloKit.AI account — the same ones our SOC 2 examination covers.
Encryption everywhere
TLS in transit and encryption at rest for all customer data.
Least-privilege access
Role-based access with mandatory MFA on every internal system.
Hardened infrastructure
Reputable cloud providers with isolated, internal-only services.
Continuous monitoring
Centralized logging and alerting to catch anomalies fast.
Vulnerability management
Dependency auditing in CI and timely patching of known issues.
Incident response
A defined process to triage, contain, and notify without delay.
The frameworks, in detail
What each standard means for how we handle your data — and how to exercise your rights.
SOC 2 Type II
Audit in progress
Our security program is built on the AICPA Trust Services Criteria, with controls mapped to the Security, Availability, and Confidentiality categories.
Security — least-privilege access, MFA, network segmentation, and continuous monitoring across our infrastructure.
Availability — capacity planning, automated backups, and disaster-recovery procedures so the service stays available as committed.
Confidentiality — encryption of customer data in transit and at rest, with access restricted to personnel with a business need.
The examination is underway; the Type II report and bridge letter will be available under NDA once issued. Email security@flokitai.com to be notified.
GDPR
Compliant
For individuals in the European Economic Area and the United Kingdom, we process personal data in line with the General Data Protection Regulation.
Lawful basis — legitimate interests, consent, and steps taken to enter into a contract, as applicable.
Your rights — access, rectification, erasure, restriction, portability, and the right to object.
Data Processing Agreement — a GDPR-compliant DPA including the EU Standard Contractual Clauses is available on request.
International transfers — where data leaves the EEA/UK, we rely on Standard Contractual Clauses and equivalent safeguards.
Subprocessors — vetted vendors bound by data-protection terms; the current list is available on request.