Security at CheckFlow

How we protect the processes and data your team runs on CheckFlow.

This page summarises the measures in place. The full detail, including our governance framework and subprocessors, is in our security statement.

What we have in place

Hosted on Microsoft Azure

Primary hosting is Microsoft Azure in the United States. Microsoft runs a physical security programme with multiple independent certifications, including SOC 2.

Read the detail

Encrypted in transit

Web connections to the CheckFlow service use TLS 1.2 and above.

Read the detail

Frequent, geo-replicated backups

Full backups weekly, differential backups every 12 hours, and transaction log backups every 5 to 10 minutes, stored in blobs geo-replicated to a paired data centre.

Read the detail

Flexible, controlled sign-in

Sign in with a Google or Microsoft account, your own SSO provider, or email and password. Email sign-in requires address confirmation and supports two-factor authentication.

Read the detail

Access control and admin tools

Administrators see user activity and manage status and permissions centrally. Users control who can access checklists, tasks and templates, and guests can be invited with limited access.

Read the detail

EU data residency on request

Other regions, including the EU, are available on request for customers who need data stored in a particular region. Backups of EU-hosted data stay within the EU.

See subprocessors

Security in how we build

Every CheckFlow employee signs a Data Access Policy, and access rights follow their job function and role.

Code changes go through automated tests, manual review, and a staging environment before reaching production, with an additional security review for sensitive changes. A suite of automated tests checks that access control rules are written correctly and enforced as expected, and we work with third-party security professionals to test our code for common exploits and scan our production servers.

The governance framework behind all of this, including scope, ownership, incident response and review, is set out in our Information Security Policy.

Policies and agreements

Security Statement Information Security Policy Privacy Policy GDPR Subprocessors All terms and policies

Have a security question or need to report something? Get in touch and we will respond within 24 hours.