Trust center
Security built for public infrastructure.
Cities trust CivicFlow with residents’ reports and the work that keeps streets safe. Here’s how we protect that data — and how you can verify it.
Compliance & controls
Security work you can verify.
Our security pack, penetration test summary and DPA are available to customers and prospects under NDA.
- Target Q1 2027
ISO 27001 certification in progress
We’re implementing our information security management system with an external auditor, with certification targeted for Q1 2027.
- Planned
SOC 2 Type I planned
A SOC 2 Type I audit is planned after ISO 27001. Until then, we share our controls overview and answer your questionnaire.
- EU
GDPR & EU data residency
Contracted through CivicFlow Technologies S.L. in Madrid. EU customers are hosted in Frankfurt, with backups in a second EU region in Amsterdam.
- AES-256 · TLS 1.3
Encryption everywhere
AES-256 at rest and TLS 1.3 in transit, with per-region keys rotated automatically.
- SAML · OIDC
SSO, SAML & SCIM
Single sign-on with any SAML or OIDC identity provider, and automatic provisioning with SCIM.
- RBAC
Role-based access & audit logs
Granular roles by department and district. Every view, export and change is logged.
- Enterprise
99.99% uptime SLA
Multi-zone deployment with automatic failover, backed by service credits.
- Aug 2026
Annual third-party penetration test
An independent firm tests the platform every year — the first was completed in August 2026 — plus continuous scanning. Summary on request.
Data handling
Collect less, keep it close, log every access.
-
Resident PII minimization
A report needs a location and a description — not an identity. Names and contact details are optional, stored separately and hidden from field crews.
-
Retention policies
Each city sets retention per category. Personal data is deleted or anonymized automatically when it expires, and every deletion is logged.
-
Data processing agreement
Every customer signs our DPA with standard contractual clauses. Your city stays the controller and can export everything at any time.
Infrastructure
Simple architecture, in-region by design.
Every request passes an edge layer before it reaches the application in the customer’s region. Backups replicate to a second EU region.
- Production access needs SSO, a hardware key and just-in-time approval
- Point-in-time recovery for 35 days; restores tested every quarter
- Infrastructure as code, with peer review for every change
Subprocessors
Who helps us run CivicFlow.
A short list of vetted subprocessors, all bound by data processing agreements. Customers are notified 30 days before any change.
| Service | Purpose | Location | Data processed |
|---|---|---|---|
| Cloud infrastructure — EU | Hosting, compute and databases | Frankfurt, DE | All customer data |
| Backup storage — EU | Encrypted backups | Amsterdam, NL | All customer data, encrypted |
| Email delivery — EU | Notifications to residents and staff | EU | Email address, message content |
| SMS delivery — EU | Text notifications to residents | EU | Phone number, message content |
| Error monitoring — EU | Application errors and performance | EU | Technical metadata, pseudonymized IDs |
| Support desk — EU | Customer support tickets | EU | Staff contact details, ticket content |
Responsible disclosure
Found a vulnerability? Tell us.
We welcome reports from security researchers. Email the details to our security team and encrypt sensitive findings with our PGP key.
- Security contact
- security@civicflow.site
- PGP fingerprint
-
4F2A 9C1E 7B3D 0A58 E6C4 91D7 2B8F 5E03 C6A1 7D94
Our commitments
- We acknowledge every report within two business days and keep you updated.
- We ask for 90 days to fix an issue before public disclosure.
- Safe harbor: good-faith research that follows this policy won’t face legal action from us.
- With your permission, we credit researchers in our release notes.
Please don’t
- Run denial-of-service or social engineering attacks
- Access, change or keep data that isn’t yours
- Point automated scanners at customer workspaces
FAQ
Common security questions.
Where is our data stored?
EU customers are hosted in Frankfurt, with encrypted backups in a second EU region in Amsterdam. These are data-center regions, separate from our Madrid headquarters. Customers outside Europe can choose our US-East region. Data stays in the region you choose.
Can CivicFlow staff see our data?
Only when you grant temporary access for a support case. Access is time-limited, needs approval and appears in your audit log.
Will you complete our security questionnaire?
Yes. We regularly answer tender questionnaires and standard frameworks. Contact us and we’ll share our standard security pack first.
Can we run CivicFlow on-premises?
Enterprise customers can choose a sovereign-cloud or on-premises deployment. Ask our team for the reference architecture.
How would you notify us of an incident?
We notify affected customers without undue delay — within 48 hours of confirming a personal data breach — and send updates until it is resolved.
Need our security documentation?
Request our security pack, penetration test summary, DPA or a completed questionnaire. We usually reply within one business day.