Security
How Flo keeps your data safe
Legal compliance
Third-party audits
Physical and environmental security
Product security
Servers and networking
We use AWS to host all production environments. AWS is designed to help us build a secure, high-performing, resilient, and efficient infrastructure for our app. AWS data centers are secure by design and SOC 1, SOC 2, and SOC 3 certified. For added security, we also use additional AWS services such as a virtual private cloud (VPC) and AWS multi-account infrastructure. To secure communication over the network, we use HTTPS protocol encrypted using Transport Layer Security.
We use AWS to host all production environments. AWS is designed to help us build a secure, high-performing, resilient, and efficient infrastructure for our app. AWS data centers are secure by design and SOC 1, SOC 2, and SOC 3 certified. For added security, we also use additional AWS services such as a virtual private cloud (VPC) and AWS multi-account infrastructure. To secure communication over the network, we use HTTPS protocol encrypted using Transport Layer Security.
Encryption
We use AWS Key Management Service to create and manage keys and control the use of encryption across a wide range of AWS services and our app.
We use AWS Key Management Service to create and manage keys and control the use of encryption across a wide range of AWS services and our app.
Storage
Flo stores all data such as metadata, activity, original files, and customer’s data in different places.
Flo stores all data such as metadata, activity, original files, and customer’s data in different places.
Isolated environments
The production network is isolated from other staging, development, and infrastructure environments. Every environment is located in a separate AWS account on separate VPC networks to make our app as secure as possible.
The production network is isolated from other staging, development, and infrastructure environments. Every environment is located in a separate AWS account on separate VPC networks to make our app as secure as possible.
Customer payment data
All payments are processed by the App Store, Google Play, or Stripe, which take full responsibility for payment security.
All payments are processed by the App Store, Google Play, or Stripe, which take full responsibility for payment security.
Secure by design
Service levels and backups
System monitoring and alerting
Vulnerability (penetration) testing
Traffic management
Incident response and data breach notification
Security as part of Flo corporate culture
Contact us
If you have any questions or suggestions regarding security at Flo, send us a note at security@flo.health. We also operate a Responsible Vulnerability Disclosure Program.