Skip to content

trust

floo protects customer data with least-privilege access controls, workload isolation, encryption, and continuous monitoring.

operator
floo labs Inc
reviewed
July 10, 2026

security

workload isolation
Customer applications are isolated from one another at runtime.
encryption
Stored customer secrets are encrypted at rest. Traffic to floo endpoints uses TLS.
access control
Organization membership and role are checked before data is returned. Removing a member invalidates active sessions.
monitoring and audit
Sensitive organization actions are logged. Production errors and service health are monitored.

subprocessors

Current floo subprocessors and service categories
providerservice
Google Cloudcloud infrastructure and managed services
GitHubsource control and code delivery
WorkOSauthentication and identity
Stripepayments and billing
Resendtransactional email
Sentrymonitoring and observability
Slackcustomer support and operational communications
Upstashcloud infrastructure and managed services

data handling

floo does not sell personal information or use advertising trackers. Privacy requests and Data Processing Agreement requests go to privacy@getfloo.com.

build logs and deploy history
90 days
runtime logs
7 days
account and app records after account closure
deleted from active systems within 30 days

compliance

SOC 2 Type II

A formal SOC 2 Type II audit is on our roadmap.

planned

documents

Security questionnaires and additional documentation are available on request from team@getfloo.com.