Policy

What we do not have: no SOC 2, no ISO 27001, no penetration test

Nobody has audited our security statements. Publishing that is more useful to you than a wall of logos.

FlowFinds Solutions holds no SOC 2 report, no ISO 27001 certificate and no PCI DSS attestation, and we have not commissioned an independent penetration test. Nobody has audited the claims on our security page; they are our own description of our own system. We are a young company and these are the honest consequences of that.

What we do operate, we describe as decisions rather than badges. Infrastructure we run ourselves inside the European Union, behind a network provider that terminates TLS and absorbs hostile traffic before it reaches the origin. Per-purpose databases rather than customer data spread across managed third-party stores, which keeps the number of parties holding a copy small enough to name — and we name them. Sign-in by single-use emailed link, so there is no password database to breach, with the plain consequence stated: whoever controls the mailbox controls the account.

Tenant isolation is the control we test hardest, because its failure would be the worst. Sessions are opaque identifiers whose reach is decided server-side. Administrative access is least-privilege and logged. Dependencies are kept deliberately few — the payment client and the backend are written against the standard library rather than an SDK, which removes a supply-chain surface instead of managing one.

If a formal report is a hard requirement for you, tell us. Knowing which customers need one is how it gets prioritised, and when we obtain one it will appear on the security page with its date and its scope.

Read next

The full security posture, including the gaps.

More from FlowFinds

To fact-check anything above before you publish it, write to [email protected].