
Flo is audited for SOC 2 Type II compliance annually and partners with Vanta for continuous monitoring
Hosted on AWS exclusively in the U.S. with SOC 1, SOC 2 and ISO 27001 certified data centers, monitored 24/7
Secure data encryption in-transit and at rest using AES 256-bit
Multi-factor authentication (MFA) can be enabled for admin users across your account. SSO can also be configured for admin users with industry leading connection providers (SAML, Microsoft Azure, ADFS, and Okta Workforce).
All users with a login must follow complex password requirements, and cryptographic keys are all encrypted in line with industry standards (Bcrypt and AES 256).
Admin users access the platform via their unique login credentials. Non-admin users access the platform via unique, one-time access links (verified using their email) and are not able to view or edit information about other users. Internal employees at Flo follow a Rules Based Access Control (RBAC) policy.
Historical and current uptime and status can be viewed on our status page, which provides the most up-to-date information.
Flo does not sell user data to third parties.
Our platform is hosted on AWS. All data is stored in the U.S. on AWS, and we utilize multiple availability zones for additional redundancies. Flo utilizes a multi-tenant environment.
Flo is entirely cloud-based and requires no on-premise hardware or installation. Our platform will not actively pull any data from your internal systems/databases unless configured to do so via custom integrations during implementation.
AWS provides security and system event and log data, as well as network data flow logs.
Flo uses AWS Guard Duty as well as conducts regular penetration testing via a verified third-party vendor.
All data sent to or from Flo is encrypted in transit using AES 256 bit encryption, as well as at rest using the same protection.
Flo partners with Daily.co, a leading video chat platform. You can review their security policies here.
Flo is continuously monitored for compliance under our successful SOC 2 Type II Report across all Engineering and HR/Operations facets.
Flo maintains ongoing compliance with the General Data Protection Regulation (GDPR) through company-wide policies and practices that govern data protection across all business functions.
We conduct background checks on all new employees in accordance with local laws, including employment verification and criminal checks. Employment contracts include confidentiality provisions.
All employees undergo annual security and awareness training and are monitored for device compliance. Employees also review company-wide IT Security policies, which are updated annually.
Flo has separate Incident Response and Business Continuity procedures that are tested regularly.
Flo AI functionality meets the highest security and data privacy standards of law firms and aims to support human judgment rather than replace it. Hiring, promotion, and development decisions stay with the people responsible for them. The protections that govern the rest of the Flo platform apply to every AI feature, with a few additions specific to how the AI works.
Flo AI is powered by the industry's leading LLMs, and we never stop evaluating. Our team continuously researches, tests, and benchmarks new models so our customers always get the strongest combination of performance, accuracy, and security.
Flo AI is built to deliver the most relevant answers to your firm's questions. We enrich every interaction with the right context about your firm and your data, so each response is thorough, meaningful, and grounded in what actually matters to you. Your data is never used to train models, so you maintain the same level of data privacy in Flo you rely on today.
Your data stays locked down. The AI doesn't get free rein over your database. It can only ask approved questions against an approved catalog of data — think of it like a bank teller who can look up your balance but can never walk into the vault.
Everything is on the record. Every question asked and every answer given is logged and auditable. Nothing happens in the dark.
Flo AI only sees what you're allowed to see as a Flo administrator in your account. Permissions are enforced by the system, not by the AI. That means the AI can't be tricked, sweet-talked, or confused into showing one customer's data to another.
Flo AI is intentionally read-only. The AI can look, but it can never change, delete, or export your data.
AI features use the same AES 256 encryption in transit and at rest as the rest of Flo.
Flo's SOC 2 Type II audit coverage extends across the platform, including its AI features.
Flo AI surfaces insights and drafts. Decisions stay with the people accountable for them.
The model currently powering Flo AI, Claude Opus by Anthropic, is subject to extensive testing and evaluation for safety, security, and reliability, documented in a public system card.