Skip to content

Commit a6c679f

Browse files
committed
added security faq and other docs pointing to trust.flagsmith.com
1 parent 34b9e67 commit a6c679f

4 files changed

Lines changed: 93 additions & 5 deletions

File tree

docs/docs/support/faq/account-billing-organisation.mdx

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -12,10 +12,6 @@ import Link from '@docusaurus/Link';
1212

1313
<div className="faq-content">
1414

15-
### Is Flagsmith SOC 2 certified?
16-
17-
Yes, Flagsmith is SOC 2 Type 2 certified.
18-
1915
### How do I delete an Organisation?
2016
Go to **Organisation** > **Manage**. Scroll to the very bottom, click the trash can icon next to "Delete Organisation," and confirm the name. This is irreversible.
2117

@@ -65,8 +61,16 @@ Go to **Organisation** > **Edit** > **Manage Invoices**.
6561

6662
**Related:** [How do I update my payment details?](#how-do-i-update-my-payment-details)
6763

64+
### Is Flagsmith SOC 2 certified?
65+
66+
Yes, Flagsmith is SOC 2 Type 2 certified. You can request the report, along with our other certifications and security
67+
documentation, through the [Flagsmith Trust Centre](https://trust.flagsmith.com).
68+
69+
**Related:** [Security & Compliance FAQ](/support/faq/security-compliance)
70+
6871
</div>
6972

7073
## Related FAQ Categories
7174

7275
- [Open Source & Self-Hosted](/support/faq/open-source-self-hosted) - Questions about SSO and authentication in self-hosted deployments
76+
- [Security & Compliance](/support/faq/security-compliance) - Questions about SOC 2, ISO 27001, GDPR and vendor reviews

docs/docs/support/faq/index.mdx

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,7 @@ import Link from '@docusaurus/Link';
1818
<li><Link to="/support/faq/feature-flags-remote-config#what-is-the-difference-between-feature-flag-and-remote-config">What is the difference between Feature Flag and Remote Config?</Link></li>
1919
<li><Link to="/support/faq/user-identity-management#how-do-i-identify-an-anonymous-user-what-about-running-ab-tests-with-anonymous-users">How do I identify an anonymous user?</Link></li>
2020
<li><Link to="/support/faq/segments-targeting#does-the--split-segment-feature-work-for-non-identified-users">Does the % split segment feature work for non-identified users?</Link></li>
21+
<li><Link to="/support/faq/security-compliance#is-flagsmith-soc-2-certified">Is Flagsmith SOC 2 certified?</Link></li>
2122
</ul>
2223
</div>
2324

@@ -72,6 +73,13 @@ import Link from '@docusaurus/Link';
7273
</div>
7374
<p>Hosting, API endpoints, Edge API, webhooks, A/B test bucketing</p>
7475
</Link>
76+
77+
<Link to="/support/faq/security-compliance" className="faq-category-card">
78+
<div className="faq-category-header">
79+
<h3>Security & Compliance</h3>
80+
</div>
81+
<p>SOC 2, ISO 27001, GDPR, penetration tests, sub-processors, security questionnaires</p>
82+
</Link>
7583
</div>
7684
</div>
7785

Lines changed: 63 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,63 @@
1+
---
2+
title: Security & Compliance - FAQ
3+
sidebar_label: Security & Compliance
4+
sidebar_position: 8
5+
description:
6+
Flagsmith security and compliance FAQ - SOC 2 Type 2, ISO 27001, GDPR, penetration tests, sub-processors and security
7+
questionnaires.
8+
keywords:
9+
- SOC 2
10+
- SOC2
11+
- ISO 27001
12+
- GDPR
13+
- DPA
14+
- penetration test
15+
- sub-processors
16+
- security questionnaire
17+
- compliance
18+
- trust centre
19+
---
20+
21+
import Link from '@docusaurus/Link';
22+
23+
<span id="top" />
24+
25+
<Link to="/support/faq">← Back to FAQ</Link>
26+
27+
<div className="faq-content">
28+
29+
Security, compliance and vendor review documentation lives in the
30+
**[Flagsmith Trust Centre](https://trust.flagsmith.com)**. It is the single, current source
31+
for our certifications, reports and policies — start there for any of the questions below.
32+
33+
### Is Flagsmith SOC 2 certified?
34+
35+
Yes, Flagsmith is SOC 2 Type 2 certified. Request the report through the
36+
[Trust Centre](https://trust.flagsmith.com).
37+
38+
### How does Flagsmith handle GDPR and data processing agreements?
39+
40+
Our privacy documentation, including the DPA and the list of sub-processors, is available through the
41+
[Trust Centre](https://trust.flagsmith.com).
42+
43+
### Can you complete our vendor security questionnaire?
44+
45+
Check the [Trust Centre FAQ](https://trust.flagsmith.com/faq#1-security-governance) first — most questionnaires can be answered in full from the
46+
documentation published there, which is faster than a manual review. If something is still outstanding, contact
47+
[support@flagsmith.com](mailto:support@flagsmith.com).
48+
49+
### How do I report a security vulnerability?
50+
51+
See [CVEs and Vulnerabilities](/support/cves-and-vulnerabilities) for how to report an issue and the remediation SLAs we
52+
work to. Do not report vulnerabilities through public GitHub issues.
53+
54+
**Related documentation:** [Help and Support](/support#security-and-compliance)
55+
56+
</div>
57+
58+
## Related FAQ Categories
59+
60+
- [Account, Billing & Organisation](/support/faq/account-billing-organisation) - Questions about accounts, SSO and
61+
billing
62+
- [Open Source & Self-Hosted](/support/faq/open-source-self-hosted) - Questions about self-hosting and the Enterprise
63+
Edition

docs/docs/support/index.mdx

Lines changed: 14 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -80,7 +80,20 @@ depending on your issue type.
8080
- **In-app chat** - Click the support widget in the Flagsmith dashboard
8181
- **Email** - [support@flagsmith.com](mailto:support@flagsmith.com)
8282
- **Community** - [Discord](https://discord.gg/hFhxNtXzgm)
83-
- **Trust Centre** - [trust.flagsmith.com](https://trust.flagsmith.com)
83+
84+
### Security and Compliance
85+
86+
Security questionnaires, compliance documentation and our SOC 2 Type 2 report are handled through the
87+
**[Flagsmith Trust Centre](https://trust.flagsmith.com)** rather than the support channels above. Go there to:
88+
89+
- Review our security posture, certifications and sub-processors
90+
- Request access to compliance reports and policies
91+
- Complete or shortcut a vendor security review
92+
93+
Common questions about SOC 2, ISO 27001, GDPR and vendor security reviews are answered in the
94+
[Security & Compliance FAQ](/support/faq/security-compliance).
95+
96+
To report a security vulnerability, see [CVEs and Vulnerabilities](./cves-and-vulnerabilities.md).
8497

8598
### Enterprise Support
8699

0 commit comments

Comments
 (0)