This Security Policy outlines the measures we use to protect Picflow accounts and Customer Content, and the providers we rely on to operate the service securely. We aim beyond baseline compliance and work to keep your ideas, data, and projects confidential and secure.
Security practices
We use encryption in transit and at rest where applicable.
We restrict internal access to production systems and use access controls designed to follow least-privilege principles.
We monitor for reliability and security issues, and use logging to investigate abuse and incidents.
We maintain backups and disaster-recovery procedures to support business continuity.
Cloud & Data Center Security
Picflow is hosted on Amazon Web Services (AWS), which means that we’ve built on a foundation of security from the start. Our hosting environment is designed for redundancy and disaster recovery. Traffic to and from the Platform is encrypted in transit. Our cloud hosting providers maintain multiple certifications for their data centers, including ISO 27001 compliance, PCI certification, and SOC. We apply AWS security best practices, such as multi-factor authentication (MFA), credential rotation, and vulnerability and patch management.
Platform hosted on AWS
TLS encryption in transit
Virtual Private Cloud
Primary data center in Ireland (EU); some infrastructure and service providers may involve processing in other regions, including the United States
Server-Side Encryption
Managed DDoS protection (AWS Shield)
Well-Architected Framework (WAFR)
AWS Activate Partner program
AWS Identity and Access Management (IAM)
Payments & Credit Cards
Picflow does not store full payment card details. Picflow uses Stripe as the payment platform infrastructure and for payment processing.
PCI DSS Level 1 certification
SOC reports
Login & Authentication
Picflow does not store your password credentials. We use Clerk to provide authentication services.
GDPR Compliant
ISO27001
SSAE18/SOC 2 Type 2
ISO27018
Gold CSA STAR
PCI DSS Compliance
EU Infrastructure & GDPR Commitment
Picflow’s primary hosting location is in the European Union (Ireland). Some infrastructure and service providers may process data in other regions, including the United States. Our data center provider AWS maintains multiple certifications, including SOC and ISO27001. Data is encrypted in transit and at rest where applicable.
We are committed to complying with the General Data Protection Regulation and supporting our customers’ compliance. For more information, see our GDPR Compliance page.
Extended Enterprise Security
The Picflow Enterprise plan offers another layer of enhanced security features to match the needs of our enterprise customers:
Single Sign-on (SAML, LDAP, ADFS, Azure AD, Google, Okta)
Enforced Two-Factor Authentication (2FA) for members and externals
Additional Access Level Rights Management
Security API for reporting and monitoring account activity
Optional IP-Range Restriction Add-On
Contact
If you have questions or concerns about this Security Policy, please get in touch with us by email at help@picflow.com.