Security & Compliance

Your data is protected by the same standards as financial institutions

Last updated: January 6, 2026

GDPR Compliant
ISO 27001
SOC 2
AES-256 Encryption

Encryption & Data Protection

  • SSL/TLS encryption for all communications
  • Encryption at rest with Supabase (AES-256)
  • Strict isolation per supervisor (Row Level Security)
  • No sensitive data stored in plain text

Authentication & Access

  • OTP (One-Time Password) authentication
  • Secure Magic Links with automatic expiration
  • No passwords stored in plain text
  • Secure sessions with JWT tokens

Infrastructure & Hosting

  • Supabase hosting (SOC 2, ISO 27001 certified)
  • Google Cloud Platform for storage
  • Daily automatic backups
  • Multi-region geographic redundancy
  • 99.9% uptime guarantee (SLA)

Evidence Storage

  • Google Cloud Storage with temporary signed URLs
  • Automatic expiration of access links
  • No direct public access to files
  • Smart photo compression
  • Timestamped and geolocated metadata

Secure Payments

  • Stripe (PCI-DSS Level 1 certified)
  • No card data stored at FlowSOP
  • NET 30 billing available for Enterprise
  • Encrypted billing history
  • 3D Secure compliance

7-Year Legal Archive

  • Immutability of archived missions
  • Regulatory compliance (financial sector)
  • Timestamped PDF export with digital signature
  • Redundant and secure storage
  • Complete audit trail access

Compliance & Certifications

  • GDPR (General Data Protection Regulation)
  • Bill 25 (Quebec - Personal Information Protection)
  • ISO 27001 (via Supabase)
  • SOC 2 Type II (in progress - 2026 roadmap)
  • Transparent privacy policy

Audit & Monitoring

  • Complete access logs (magic_link_access_logs)
  • Real-time monitoring with Sentry
  • Cloud Monitoring (Google Cloud)
  • Automatic alerts for anomalies
  • Monthly security reports available

Access & Permissions

  • Strict isolation per supervisor
  • Executors: access limited to their missions only
  • No inter-organization sharing
  • Instant access revocation
  • Principle of least privilege applied

Security Reporting & Support

We take security seriously. If you discover a vulnerability, contact us immediately.

  • Dedicated email: security@flowsop.app
  • Responsible disclosure policy
  • Response guaranteed within 48h
  • Recognition program (bug bounty coming soon)

Questions about our security?

Our team is available to answer all your security and compliance questions.