We establish policies and controls, monitor compliance and prove it to third-party auditors.
Data at Rest
Customer data is fully encrypted. Even before it reaches our databases, it's encrypted at rest, ensuring maximum security against both physical and logical access attempts.
Secret Management
Superflow uses TLS 1.2 or higher everywhere data is transmitted over potentially insecure networks.
Data in transit
Application secrets are encrypted and stored securely via Google Secrets Manager and access to these values is strictly limited.
Endpoint protection
All corporate devices are centrally managed with anti-malware and equipped with Mobile Device Management (MDM) for secure configuration, including disk encryption, screen locks, and software updates. Our security alerts are monitored 24/7/365.
Security education
Superflow provides comprehensive security training toall employees upon onboarding and annually through educational modules with Vanta’s platform.
Identity and access management
Secure and streamlined access with Google SSO. We use multi-factor authentication (MFA) and role-based access control, ensuring employees only have access to necessary applications. Access is automatically revoked upon termination.
View Superflow’s Privacy Policy.
Superflow evaluates updates to regulatory and emerging frameworks continuously to evolve our program.