trust
floo protects customer data with least-privilege access controls, workload isolation, encryption, and continuous monitoring.
- operator
- floo labs Inc
- reviewed
- July 10, 2026
security
- workload isolation
- Customer applications are isolated from one another at runtime.
- encryption
- Stored customer secrets are encrypted at rest. Traffic to floo endpoints uses TLS.
- access control
- Organization membership and role are checked before data is returned. Removing a member invalidates active sessions.
- monitoring and audit
- Sensitive organization actions are logged. Production errors and service health are monitored.
subprocessors
| provider | service |
|---|---|
| Google Cloud | cloud infrastructure and managed services |
| GitHub | source control and code delivery |
| WorkOS | authentication and identity |
| Stripe | payments and billing |
| Resend | transactional email |
| Sentry | monitoring and observability |
| Slack | customer support and operational communications |
| Upstash | cloud infrastructure and managed services |
data handling
floo does not sell personal information or use advertising trackers. Privacy requests and Data Processing Agreement requests go to privacy@getfloo.com.
- build logs and deploy history
- 90 days
- runtime logs
- 7 days
- account and app records after account closure
- deleted from active systems within 30 days
compliance
SOC 2 Type II
A formal SOC 2 Type II audit is on our roadmap.
planned
documents
Security questionnaires and additional documentation are available on request from team@getfloo.com.