|
| 1 | +--- |
| 2 | +title: Security & Compliance - FAQ |
| 3 | +sidebar_label: Security & Compliance |
| 4 | +sidebar_position: 8 |
| 5 | +description: |
| 6 | + Flagsmith security and compliance FAQ - SOC 2 Type 2, ISO 27001, GDPR, penetration tests, sub-processors and security |
| 7 | + questionnaires. |
| 8 | +keywords: |
| 9 | + - SOC 2 |
| 10 | + - SOC2 |
| 11 | + - ISO 27001 |
| 12 | + - GDPR |
| 13 | + - DPA |
| 14 | + - penetration test |
| 15 | + - sub-processors |
| 16 | + - security questionnaire |
| 17 | + - compliance |
| 18 | + - trust centre |
| 19 | +--- |
| 20 | + |
| 21 | +import Link from '@docusaurus/Link'; |
| 22 | + |
| 23 | +<span id="top" /> |
| 24 | + |
| 25 | +<Link to="/support/faq">← Back to FAQ</Link> |
| 26 | + |
| 27 | +<div className="faq-content"> |
| 28 | + |
| 29 | +Security, compliance and vendor review documentation lives in the |
| 30 | +**[Flagsmith Trust Centre](https://trust.flagsmith.com)**. It is the single, current source |
| 31 | +for our certifications, reports and policies — start there for any of the questions below. |
| 32 | + |
| 33 | +### Is Flagsmith SOC 2 certified? |
| 34 | + |
| 35 | +Yes, Flagsmith is SOC 2 Type 2 certified. Request the report through the |
| 36 | +[Trust Centre](https://trust.flagsmith.com). |
| 37 | + |
| 38 | +### How does Flagsmith handle GDPR and data processing agreements? |
| 39 | + |
| 40 | +Our privacy documentation, including the DPA and the list of sub-processors, is available through the |
| 41 | +[Trust Centre](https://trust.flagsmith.com). |
| 42 | + |
| 43 | +### Can you complete our vendor security questionnaire? |
| 44 | + |
| 45 | +Check the [Trust Centre FAQ](https://trust.flagsmith.com/faq#1-security-governance) first — most questionnaires can be answered in full from the |
| 46 | +documentation published there, which is faster than a manual review. If something is still outstanding, contact |
| 47 | +[support@flagsmith.com](mailto:support@flagsmith.com). |
| 48 | + |
| 49 | +### How do I report a security vulnerability? |
| 50 | + |
| 51 | +See [CVEs and Vulnerabilities](/support/cves-and-vulnerabilities) for how to report an issue and the remediation SLAs we |
| 52 | +work to. Do not report vulnerabilities through public GitHub issues. |
| 53 | + |
| 54 | +**Related documentation:** [Help and Support](/support#security-and-compliance) |
| 55 | + |
| 56 | +</div> |
| 57 | + |
| 58 | +## Related FAQ Categories |
| 59 | + |
| 60 | +- [Account, Billing & Organisation](/support/faq/account-billing-organisation) - Questions about accounts, SSO and |
| 61 | + billing |
| 62 | +- [Open Source & Self-Hosted](/support/faq/open-source-self-hosted) - Questions about self-hosting and the Enterprise |
| 63 | + Edition |
0 commit comments