flyhelpdesk

Trust centre

How the service is secured, where your data is kept, what we commit to, and the documents behind it. Figures on this page come from the running configuration.

Certifications and audits

No third-party certification yet. The controls are mapped to SOC 2 and ISO/IEC 27001 in the product's compliance dashboard, and we share our security documentation on request.

Security questionnaires, the latest penetration-test summary and policies: ask [email protected].

Security measures

  • Encryption in transit (TLS, HSTS) and of secrets at rest with a separate key per workspace, rotatable.
  • Each workspace’s data kept apart from every other’s, enforced on every query and covered by tests.
  • Roles with least privilege; multi-factor sign-in (authenticator apps, passkeys) that the customer can require; single sign-on and SCIM; session timeouts; network allow-lists; a recent sign-in required for sensitive settings.
  • A tamper-evident audit log of access and changes, and monitoring that alerts on suspicious activity.
  • Daily encrypted backups, verified, kept off-site and restored into a scratch copy every week to prove they work.
  • Attachments scanned for malware; outbound connections to customer-set addresses checked so they cannot reach internal networks.
  • A recorded incident and breach process, and dependencies checked for known vulnerabilities on every change.

Where your data is

All workspaces of this deployment are kept in one data region, stated in your agreement.

Encrypted backups every night, kept 14 days, and restored into a scratch copy every week to prove they work.

A tamper-evident audit log, kept 730 days, which you can stream to your own SIEM.

What we commit to

  • A personal data breach is reported to you within 48 hours; a significant security incident within 24 hours (NIS2).
  • Leave whenever you like: a full export in open formats, free, at most 30 days' notice, no switching charges (EU Data Act).
  • After you leave, the workspace is deleted within 30 days, and its backups as they expire.
  • AI is labelled wherever it speaks or writes, and a person is always one step away (EU AI Act, Art. 50).

Documents

Report a vulnerability

Found a security problem? Tell us privately and we will reply within two working days, keep you informed, and not take action against good-faith research. [email protected] · security.txt