Reflow - Trust Center - Security & Privacy
Founded in 2024
Reflow recognises that the confidentiality, integrity and availability of information and data created, maintained and hosted by us are vital to the success of the business and privacy of our partners.
As a service provider/product, we understand the importance in providing clear information about our security practices, tools, resources and responsibilities within Reflow so that our customers can feel confident in choosing us as a trusted provider.
This Security Posture highlights high-level details about our steps to identify and mitigate risks, implement best practices, and continuously develop ways to improve.
Compliances
SOC 2 Type 2
Certified
HIPAA
Compliant
CPRA (formerly CCPA)
Compliant
GDPR
Compliant
Controls
Product security
- Production System User Review
- Situational Awareness For Incidents
- Vulnerability Remediation Process
Data security
- Termination of Employment
- Production Databases Access Restriction
- Multi-factor Authentication
Network security
- Impact analysis
- Limit Network Connections
- Transmission Confidentiality
App security
- Conspicuous Link To Privacy Notice
- Secure system modification
- Approval of Changes
Endpoint security
- Malicious Code Protection (Anti-Malware)
- Full Device or Container-based Encryption
- Endpoint Security Validation
Corporate security
- Code of Business Conduct
- Organizational Structure
- Competency Screening
Resources
Policies
- Operations Security Procedure
- Access Control Procedure
- Acceptable Usage Policy
- Business Continuity Plan
- System Acquisition and Development Lifecycle Policy
- Compliance Policy
Subprocessors
- 1Password - Security Software
- Linear - Ticketing Software
- Vercel - IT infrastructure
- Github App - Development software
- Cloudflare - Hosting Providers
- Heroku - IT infrastructure