Security at CheckFlow
How we protect the processes and data your team runs on CheckFlow.
This page summarises the measures in place. The full detail, including our governance framework and subprocessors, is in our security statement.
What we have in place
Hosted on Microsoft Azure
Primary hosting is Microsoft Azure in the United States. Microsoft runs a physical security programme with multiple independent certifications, including SOC 2.
Read the detailEncrypted in transit
Web connections to the CheckFlow service use TLS 1.2 and above.
Read the detailFrequent, geo-replicated backups
Full backups weekly, differential backups every 12 hours, and transaction log backups every 5 to 10 minutes, stored in blobs geo-replicated to a paired data centre.
Read the detailFlexible, controlled sign-in
Sign in with a Google or Microsoft account, your own SSO provider, or email and password. Email sign-in requires address confirmation and supports two-factor authentication.
Read the detailAccess control and admin tools
Administrators see user activity and manage status and permissions centrally. Users control who can access checklists, tasks and templates, and guests can be invited with limited access.
Read the detailEU data residency on request
Other regions, including the EU, are available on request for customers who need data stored in a particular region. Backups of EU-hosted data stay within the EU.
See subprocessorsSecurity in how we build
Every CheckFlow employee signs a Data Access Policy, and access rights follow their job function and role.
Code changes go through automated tests, manual review, and a staging environment before reaching production, with an additional security review for sensitive changes. A suite of automated tests checks that access control rules are written correctly and enforced as expected, and we work with third-party security professionals to test our code for common exploits and scan our production servers.
The governance framework behind all of this, including scope, ownership, incident response and review, is set out in our Information Security Policy.
Policies and agreements
Security Statement Information Security Policy Privacy Policy GDPR Subprocessors All terms and policies
Have a security question or need to report something? Get in touch and we will respond within 24 hours.