Information security management
FlowX.AI operates an information security management system certified against ISO/IEC 27001, covering how we govern, run and continuously improve security across the company.
Company · Trust & Compliance
FlowX.AI works with banks, insurers and other institutions where security and compliance are conditions of doing business. This page is about us as a company: what we hold, what it covers, and how to get the evidence.
iso 27001 certified · soc 2 type i completed · type ii in progress · gdpr
Certifications are not the point. They are the shortest way for a risk team to verify that the way we run the company matches what we say in the room.
Each item below names what was examined, by what standard, and as of when. Where a report exists, it is available under NDA, not summarized here.
company attestations · not product featuresThree positions, stated plainly. The product’s own security controls and the regulatory frameworks the platform maps are a separate matter and live on the platform security page.
FlowX.AI operates an information security management system certified against ISO/IEC 27001, covering how we govern, run and continuously improve security across the company.
An independent SOC 2 Type I examination confirmed that FlowX.AI’s controls were suitably designed, as of June 17, 2026, against the applicable AICPA Trust Services Criteria for Security, Availability and Confidentiality. The SOC 2 Type II examination, which tests those controls over an operating period, is in progress.
Personal data is processed under the General Data Protection Regulation: data processing terms with customers, defined retention, subject-rights handling, and privacy built into how we design and run our services.
Security questionnaires, vendor due diligence and audits all start with the same request. Here is what we share and how.
Available to customers and prospects under NDA. Ask through the contact form and we will send the NDA and the report.
Certificate details available on request through the same form.
Our privacy policy, cookie policy and contractual terms are public and linked below.
Privacy policy → · Cookie policy → · Terms & conditions → · SaaS terms → · Support policy →
Ask for the SOC 2 Type I report under NDA, the ISO 27001 details, or answers to your vendor due-diligence questions. We reply with the documents, not a deck.