SystemFlow
Compliance

A continuous compliance program, not a one-time checkbox

We treat compliance as an ongoing engineering discipline - and we do not claim certifications we have not earned. Here is exactly where each framework stands.

Frameworks

Where we stand

FrameworkStatusNotes
GDPRAlignedData minimisation, deletion within 90 days, user rights honoured.
CCPA / CPRAAlignedNo sale of personal data; access and deletion on request.
SOC 2 Type IIPlannedAudit planned as the company grows out of beta.
ISO 27001PlannedControls designed with certification in mind.
PCI DSSN/A by designCard data handled entirely by our payment provider (Stripe).
HIPAANot offeredSystemFlow is not intended for PHI workloads today.
Data residency

Where your data lives

SystemFlow runs on a single region today. Per-region data pinning and self-hosting are on the roadmap, not available yet - tell us if that's a requirement and we'll factor it into the timeline.

Subprocessors

Who we work with

Database and auth run on Supabase, billing runs through Stripe, the AI reviewer calls Anthropic's API, and transactional email goes through our SMTP provider. We'll notify customers in advance of any material change to this list.

Need a DPA or audit report?

Request documentation through the Trust Center or talk to our compliance team.