Skip to content

Trust center

Security built for public infrastructure.

Cities trust CivicFlow with residents’ reports and the work that keeps streets safe. Here’s how we protect that data — and how you can verify it.

Compliance & controls

Security work you can verify.

Our security pack, penetration test summary and DPA are available to customers and prospects under NDA.

  • Target Q1 2027

    ISO 27001 certification in progress

    We’re implementing our information security management system with an external auditor, with certification targeted for Q1 2027.

  • Planned

    SOC 2 Type I planned

    A SOC 2 Type I audit is planned after ISO 27001. Until then, we share our controls overview and answer your questionnaire.

  • EU

    GDPR & EU data residency

    Contracted through CivicFlow Technologies S.L. in Madrid. EU customers are hosted in Frankfurt, with backups in a second EU region in Amsterdam.

  • AES-256 · TLS 1.3

    Encryption everywhere

    AES-256 at rest and TLS 1.3 in transit, with per-region keys rotated automatically.

  • SAML · OIDC

    SSO, SAML & SCIM

    Single sign-on with any SAML or OIDC identity provider, and automatic provisioning with SCIM.

  • RBAC

    Role-based access & audit logs

    Granular roles by department and district. Every view, export and change is logged.

  • Enterprise

    99.99% uptime SLA

    Multi-zone deployment with automatic failover, backed by service credits.

  • Aug 2026

    Annual third-party penetration test

    An independent firm tests the platform every year — the first was completed in August 2026 — plus continuous scanning. Summary on request.

Data handling

Collect less, keep it close, log every access.

  • Resident PII minimization

    A report needs a location and a description — not an identity. Names and contact details are optional, stored separately and hidden from field crews.

  • Retention policies

    Each city sets retention per category. Personal data is deleted or anonymized automatically when it expires, and every deletion is logged.

  • Data processing agreement

    Every customer signs our DPA with standard contractual clauses. Your city stays the controller and can export everything at any time.

Infrastructure

Simple architecture, in-region by design.

Every request passes an edge layer before it reaches the application in the customer’s region. Backups replicate to a second EU region.

  • Production access needs SSO, a hardware key and just-in-time approval
  • Point-in-time recovery for 35 days; restores tested every quarter
  • Infrastructure as code, with peer review for every change
EU region · Frankfurt Residents & apps Portal · Field app · API Edge WAF · DDoS · TLS 1.3 Application Multi-zone Postgres PITR · 35 days Object storage Photos & files Backups · Amsterdam Second EU region Encrypted replication
Infrastructure diagram

Subprocessors

Who helps us run CivicFlow.

A short list of vetted subprocessors, all bound by data processing agreements. Customers are notified 30 days before any change.

Subprocessors for EU customers
Service Purpose Location Data processed
Cloud infrastructure — EU Hosting, compute and databases Frankfurt, DE All customer data
Backup storage — EU Encrypted backups Amsterdam, NL All customer data, encrypted
Email delivery — EU Notifications to residents and staff EU Email address, message content
SMS delivery — EU Text notifications to residents EU Phone number, message content
Error monitoring — EU Application errors and performance EU Technical metadata, pseudonymized IDs
Support desk — EU Customer support tickets EU Staff contact details, ticket content

Responsible disclosure

Found a vulnerability? Tell us.

We welcome reports from security researchers. Email the details to our security team and encrypt sensitive findings with our PGP key.

Security contact
security@civicflow.site
PGP fingerprint
4F2A 9C1E 7B3D 0A58 E6C4 91D7 2B8F 5E03 C6A1 7D94

Our commitments

  • We acknowledge every report within two business days and keep you updated.
  • We ask for 90 days to fix an issue before public disclosure.
  • Safe harbor: good-faith research that follows this policy won’t face legal action from us.
  • With your permission, we credit researchers in our release notes.

Please don’t

  • Run denial-of-service or social engineering attacks
  • Access, change or keep data that isn’t yours
  • Point automated scanners at customer workspaces

FAQ

Common security questions.

Where is our data stored?

EU customers are hosted in Frankfurt, with encrypted backups in a second EU region in Amsterdam. These are data-center regions, separate from our Madrid headquarters. Customers outside Europe can choose our US-East region. Data stays in the region you choose.

Can CivicFlow staff see our data?

Only when you grant temporary access for a support case. Access is time-limited, needs approval and appears in your audit log.

Will you complete our security questionnaire?

Yes. We regularly answer tender questionnaires and standard frameworks. Contact us and we’ll share our standard security pack first.

Can we run CivicFlow on-premises?

Enterprise customers can choose a sovereign-cloud or on-premises deployment. Ask our team for the reference architecture.

How would you notify us of an incident?

We notify affected customers without undue delay — within 48 hours of confirming a personal data breach — and send updates until it is resolved.

Need our security documentation?

Request our security pack, penetration test summary, DPA or a completed questionnaire. We usually reply within one business day.