Trust Center

Security & compliance,
by default.

FloKit.AI is built so growth teams can move fast without giving up control of their data. Here are the frameworks we align to, the controls we run, and how to get what your security review needs.

How we protect your data

The core controls behind every FloKit.AI account — the same ones our SOC 2 examination covers.

Encryption everywhere

TLS in transit and encryption at rest for all customer data.

Least-privilege access

Role-based access with mandatory MFA on every internal system.

Hardened infrastructure

Reputable cloud providers with isolated, internal-only services.

Continuous monitoring

Centralized logging and alerting to catch anomalies fast.

Vulnerability management

Dependency auditing in CI and timely patching of known issues.

Incident response

A defined process to triage, contain, and notify without delay.

The frameworks, in detail

What each standard means for how we handle your data — and how to exercise your rights.

SOC 2 Type II

Audit in progress

Our security program is built on the AICPA Trust Services Criteria, with controls mapped to the Security, Availability, and Confidentiality categories.

  • Security — least-privilege access, MFA, network segmentation, and continuous monitoring across our infrastructure.
  • Availability — capacity planning, automated backups, and disaster-recovery procedures so the service stays available as committed.
  • Confidentiality — encryption of customer data in transit and at rest, with access restricted to personnel with a business need.

The examination is underway; the Type II report and bridge letter will be available under NDA once issued. Email security@flokitai.com to be notified.

GDPR

Compliant

For individuals in the European Economic Area and the United Kingdom, we process personal data in line with the General Data Protection Regulation.

  • Lawful basis — legitimate interests, consent, and steps taken to enter into a contract, as applicable.
  • Your rights — access, rectification, erasure, restriction, portability, and the right to object.
  • Data Processing Agreement — a GDPR-compliant DPA including the EU Standard Contractual Clauses is available on request.
  • International transfers — where data leaves the EEA/UK, we rely on Standard Contractual Clauses and equivalent safeguards.
  • Subprocessors — vetted vendors bound by data-protection terms; the current list is available on request.

Data-protection questions and requests: privacy@flokitai.com.

CCPA / CPRA

Compliant

For California residents, we honor the California Consumer Privacy Act, as amended by the CPRA.

  • Right to know — what personal information we collect, its sources, and the purposes.
  • Right to delete — request deletion of personal information we hold about you.
  • Right to correct — request correction of inaccurate personal information.
  • Right to opt out — we do not sell or share personal information as those terms are defined under the CCPA.
  • Non-discrimination — we will not deny service or offer inferior terms for exercising your rights.

To submit a request, email privacy@flokitai.com. We verify requests before responding, within the timelines required by law.

Request our security package

Customers and prospects can request our SOC 2 status, DPA, subprocessor list, and security overview.

Email security@flokitai.com

Report a vulnerability

Found a security issue? We appreciate responsible disclosure — send details and steps to reproduce and we'll acknowledge your report.

Report an issue

Data handling is described in our Privacy Policy, Cookie Policy, and Terms of Use. Last updated: July 1, 2026.