SOC2C

Is this your company? Buyers are checking Topicflow here. Claim topicflow.com free to control the listing, earn the badge buyers trust, and see who's evaluating you.

Claim free
Topicflow logo

Topicflow

Trust level
Listed
Unverified

Sourced from public information. Not yet verified by the company.

Topicflow is SOC 2 Type II compliant.

Framework
Auditor
Last report
Renewal
View official trust center ↗

About

Welcome to Topicflow's security portal. Use this portal to learn about our security posture and request access to our security documentation. For any security related questions that haven't been addressed on this page, please email us at [hello@topicflow.com](mailto:hello@topicflow.com).

Compliance & infrastructure

Hosting
AWS

Documents

2

Subprocessors

11
  • A
    Amazon Web Services · Infrastructure Hosting
    United States
  • S
    Sumo Logic · Cloud monitoring
    United States
  • I
    Intercom · Customer support
    United States
  • O
    OpenAI · Engineering
    United States
  • R
    Recall · Online Meeting Recording
    United States
  • S
    Sentry · Cloud monitoring
    United States
  • S
    Slack · Collaboration
    United States
  • W
    WorkOS · Engineering
    United States
  • P
    Pusher · Engineering
    United States
  • I
    Imgix · Engineering
    United States
  • F
    FullStory · Product and design
    United States

Compliance leadership

The person who leads Topicflow's SOC 2 isn't listed yet. Claim this profile to add it.

Penetration test

Unknown. Topicflow's penetration test vendor isn't listed yet.

Claim this profile to add it.

This listing is partial

6/11 details · 55%

SOC2C shows the verified essentials. 5 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.

  • Auditorraises trust
    Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
  • Report dateraises trust
    Add your most recent report period so buyers see how current your SOC 2 is.
  • Renewal date
    Add your renewal window so buyers know your coverage is active.
  • Other certifications
    List your other frameworks (ISO 27001, HIPAA, PCI DSS) the way your trust center does.
  • Security controls
    Confirm key controls (encryption, MFA/SSO, annual pen test, BCP/DR) buyers screen for.
Claim free to control your listing

Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.

Frequently asked

Is Topicflow SOC 2 compliant?
Topicflow is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Topicflow SOC 2 Type I or Type II?
Topicflow is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Topicflow's SOC 2 for a vendor risk assessment?
Yes. Topicflow's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Topicflow penetration tested?
Yes — Topicflow undergoes third-party penetration testing as part of its security program. The pentest vendor is listed on its SOC2C profile.
Can I get Topicflow's SOC 2 report?
Topicflow's SOC 2 report is available on request. Request access through SOC2C and we coordinate the company-side NDA and delivery.

Answers published by Topicflow

Reproduced from Topicflow's own trust center. These are the company's statements about its security practices — SOC2C has not tested or verified them, and they may have changed since we last read the page. Check the source ↗

How long is data stored?
After a user gives Topicflow permission to access their Google or Microsoft calendar, we will periodically fetch event data from the calendar. We store information such as the title and time of an event in our database, so that we can present that information in the Topicflow user interface. We only fetch events 60 days into the future, and if an event is not used in Topicflow (if no topics are added to the meeting agenda), we delete all information about the event from our database after 30 days. A user may request that their information or events are deleted from our database at any time. Before doing so, they are able to export their data in order to retain it themselves.
What types of authentication are supported?
Topicflow does not store any usernames or passwords, as we only support SSO-based authentication with Google or Microsoft. Users may choose to use multi-factor authentication with their Google/Microsoft account for added security. Topicflow sessions are limited to a reasonable length of time, so that users must periodically re-authenticate.
What is your backup policy?
Our databases are backed up daily, and backups are retained for 30 days. We practice the database recovery process at least once a year, to ensure that our disaster recovery procedures are working.
Where are your servers located?
Topicflow servers are all hosted with AWS, currently in US-based datacenters. AWS has multiple security certifications in place, such as SOC2. Our AWS-hosted servers are contained within virtual private networks, and all administrative access to the servers themselves requires a secure VPN connection. Access to AWS requires multi-factor authentication. We capture audit logs from AWS to an external logging system. Our infrastructure is defined using an IaC (Infrastructure as Code) tool, to ensure that all changes are logged and that the infrastructure can be reproduced as needed. Our AWS services are hosted across multiple availability zones, to minimize the chance of downtime if AWS experiences issues. Although our services are currently hosted in a single AWS region, our provisioning is highly automated and we are able to restart the service in a different region quickly.
Do you encrypt data at rest?
All communication between our internal services and between users and our services is encrypted using TLS. All data at rest is encrypted using AES-256 encryption.

Business & Industrial peers that completed SOC 2