Is this your company?Buyers are checking Vecflow here. Claim vecflow.ai free to control the listing, earn the badge buyers trust, and see who's evaluating you.
Welcome to the VecFlow Security Portal! This portal provides an overview of our commitment to security and compliance. You can find our certifications, security practices, and explore details on our controls.
SOC2C shows the verified essentials. 7 details are not yet provided by the company. Trust centers list more, so we invite the owner to fill the gaps here.
Auditorraises trust
Add the CPA firm that issued your SOC 2 so buyers can verify who signed it.
Report dateraises trust
Add your most recent report period so buyers see how current your SOC 2 is.
Renewal date
Add your renewal window so buyers know your coverage is active.
Documents
List the documents you share (SOC 2 report, SOC 3, pen-test summary, DPA) and whether each is public or on request.
Subprocessors
List your subprocessors so buyers can assess fourth-party risk, the way your trust center does.
Hosting
Add where you host (AWS, GCP, Azure) and data residency.
Verify your work email to take ownership, earn the badge buyers trust, and add the details that win deals.
Frequently asked
Is Vecflow SOC 2 compliant?
Vecflow is SOC 2 Type II compliant. On SOC2C this listing is Listed.
Is Vecflow ISO 27001 certified?
According to Vecflow's public trust center, Vecflow is ISO 27001 certified. On SOC2C this listing is Listed.
Is Vecflow SOC 2 Type I or Type II?
Vecflow is SOC 2 Type II compliant. A Type II report covers how security controls operated over a period (typically 3 to 12 months), a stronger signal than a point-in-time Type I.
Can I use Vecflow's SOC 2 for a vendor risk assessment?
Yes. Vecflow's SOC 2 status, frameworks, auditor, and renewal timing are on SOC2C for vendor risk and security reviews. Request the underlying report through SOC2C to complete your third-party risk file.
Is Vecflow penetration tested?
Vecflow hasn't listed its penetration testing on SOC2C yet. SOC 2 Type II programs typically include periodic third-party penetration tests; the company can add who performed theirs.
Is Vecflow secure?
Security isn't a single yes/no, but Vecflow is SOC 2 Type II compliant and holds SOC 2 Type II, ISO 27001. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
Does Vecflow have a bug bounty or vulnerability disclosure program?
Vecflow hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@vecflow.ai or via a /security page (Vecflow lists a security contact).
Who are Vecflow's subprocessors?
Vecflow's subprocessors aren't listed on SOC2C yet. The company can add them so buyers can assess fourth-party risk.
Where does Vecflow host or store data?
Vecflow's hosting and data-residency details aren't listed on SOC2C yet. The company can add where it hosts (AWS, GCP, Azure) and which data it handles.
Where is Vecflow's trust center or security page?
Vecflow's trust center is at https://trust.vecflow.ai. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.
How does August approach security?
August's security approach is comprehensive, focusing on both preventive measures and swift incident response. We enforce strict internal authentication and access control using unique user identifiers and hardware-backed FIDO2 multi-factor authentication for all personnel. Employee devices are centrally managed to adhere to our security policies, with data redundantly backed up across multiple data centers, primarily in the United States, unless otherwise specified by the client. August's secure development lifecycle incorporates industry best practices, including rigorous code reviews, static and dynamic application security testing. Our infrastructure is protected through network segmentation, firewalls, and Web Application Firewalls (WAFs), ensuring unauthorized access is prevented. Continuous security monitoring and intrusion detection systems are in place to identify and mitigate potential threats. In case of a security incident, August follows established incident response policies and regularly tested playbooks. Additionally, we conduct regular third-party offensive security assessments to evaluate and strengthen our security posture comprehensively.
Which information does August have available to accelerate the IT Security/Risk Review process?
Under a Non-Disclosure Agreement (NDA), August can provide our "Security Welcome Packet," which includes detailed information on our security practices. We are also prepared to share our SOC 2 Type 2 report, along with industry-standard questionnaires such as VSA-Full, SIG Lite, and CAIQv4, to expedite the Security/Risk review process.
How do you authenticate customers?
August leverages Single Sign-On (SSO) with SAML for customer authentication. This allows firm administrators to centrally manage access to August and enforce security policies effectively. Users can seamlessly log in using their firm’s credentials, eliminating the need for an additional password.
Where are your servers located?
August operates on Cloud providers, with all data processing and storage primarily occurring in the United States. We also offer support for data storage in other regions upon request to accommodate client needs.
Can I request data deletion or export?
Yes, August provides customers with the ability to request data deletion or export. We offer secure and compliant methods for data export, allowing you to retrieve your data in a commonly used format. For data deletion, we ensure that all data is permanently removed from our systems in accordance with industry best practices.
What is August's data retention policy?
August retains customer data only for as long as it is necessary to fulfill the purposes for which it was collected, including for legal, regulatory, and operational reasons. Upon the termination of a customer’s contract, we offer options for data retrieval or deletion in accordance with applicable laws and contractual agreements.