Skip to main content

Security Policy

Learn which security measures we are taking to protect your account.

Updated this week

This Security Policy outlines the measures we use to protect Picflow accounts and Customer Content, and the providers we rely on to operate the service securely. We aim beyond baseline compliance and work to keep your ideas, data, and projects confidential and secure.

Security practices

  • We use encryption in transit and at rest where applicable.

  • We restrict internal access to production systems and use access controls designed to follow least-privilege principles.

  • We monitor for reliability and security issues, and use logging to investigate abuse and incidents.

  • We maintain backups and disaster-recovery procedures to support business continuity.

Cloud & Data Center Security

Picflow is hosted on Amazon Web Services (AWS), which means that we’ve built on a foundation of security from the start. Our hosting environment is designed for redundancy and disaster recovery. Traffic to and from the Platform is encrypted in transit. Our cloud hosting providers maintain multiple certifications for their data centers, including ISO 27001 compliance, PCI certification, and SOC. We apply AWS security best practices, such as multi-factor authentication (MFA), credential rotation, and vulnerability and patch management.

  • Platform hosted on AWS

  • TLS encryption in transit

  • Virtual Private Cloud

  • Primary data center in Ireland (EU); some infrastructure and service providers may involve processing in other regions, including the United States

  • Server-Side Encryption

  • Managed DDoS protection (AWS Shield)

  • Well-Architected Framework (WAFR)

  • AWS Activate Partner program

  • AWS Identity and Access Management (IAM)

Payments & Credit Cards

Picflow does not store full payment card details. Picflow uses Stripe as the payment platform infrastructure and for payment processing.

  • PCI DSS Level 1 certification

  • SOC reports

Login & Authentication

Picflow does not store your password credentials. We use Clerk to provide authentication services.

  • GDPR Compliant

  • ISO27001

  • SSAE18/SOC 2 Type 2

  • ISO27018

  • Gold CSA STAR

  • PCI DSS Compliance

EU Infrastructure & GDPR Commitment

Picflow’s primary hosting location is in the European Union (Ireland). Some infrastructure and service providers may process data in other regions, including the United States. Our data center provider AWS maintains multiple certifications, including SOC and ISO27001. Data is encrypted in transit and at rest where applicable.

We are committed to complying with the General Data Protection Regulation and supporting our customers’ compliance. For more information, see our GDPR Compliance page.

Extended Enterprise Security

The Picflow Enterprise plan offers another layer of enhanced security features to match the needs of our enterprise customers:

  • Single Sign-on (SAML, LDAP, ADFS, Azure AD, Google, Okta)

  • Enforced Two-Factor Authentication (2FA) for members and externals

  • Additional Access Level Rights Management

  • Security API for reporting and monitoring account activity

  • Optional IP-Range Restriction Add-On


Contact

If you have questions or concerns about this Security Policy, please get in touch with us by email at help@picflow.com.

Did this answer your question?