Trust & Security
Your Data, Protected
Security isn't a feature โ it's foundational to everything we build. Here's how we keep your data safe.
Encryption
Roadmap
Compliant
In Transit
Uptime
Security Measures
Data Encryption
All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Your clients' sensitive information is protected at every step โ from form submission to file upload to database storage.
SOC 2 Compliance Roadmap
We're actively working toward SOC 2 Type II certification. Our infrastructure and processes are built on SOC 2 principles: security, availability, processing integrity, confidentiality, and privacy.
GDPR Compliance
OnboardFlow is fully GDPR compliant. We offer Data Processing Agreements (DPAs), support data export and deletion requests, implement data minimization, and never sell your data to third parties.
Regular Security Audits
We conduct regular security assessments, vulnerability scanning, and penetration testing. Our codebase undergoes automated security scanning with every deployment.
Data Hosting
OnboardFlow is hosted on Vercel's edge network with database infrastructure on Neon (PostgreSQL). Both providers maintain SOC 2 Type II certification and offer enterprise-grade reliability with 99.99% uptime SLAs.
Access Controls
Role-based access control (RBAC) ensures team members only see what they need. All admin actions are logged in an audit trail. Two-factor authentication (2FA) is available for all accounts.
Security Practices
- โSecure software development lifecycle (SSDLC)
- โAutomated dependency vulnerability scanning
- โEnvironment isolation (production, staging, development)
- โEncrypted backups with point-in-time recovery
- โIncident response plan with 24-hour notification commitment
- โEmployee security training and access reviews
- โVendor security assessments for all sub-processors
- โData retention policies with automatic purging
Have security questions?
We're happy to discuss our security practices, provide our security questionnaire, or arrange a call with our team.