Last updated: 1 May 2026
PsychFlo processes sensitive behavioural metadata on behalf of employers globally. This page describes the technical and organisational security measures we apply to protect that data.
SECURITY POSTURE SUMMARY
Encryption in transit
All data transmitted between client browsers, our application servers, and third-party APIs is encrypted using TLS 1.3. HTTP connections are automatically redirected to HTTPS. API endpoints do not accept unencrypted connections.
Encryption at rest
All data stored in our database (Supabase, hosted on AWS eu-west-2, London) is encrypted at rest using AES-256. Database backups are encrypted using the same standard. Encryption keys are managed by Supabase's key management service and rotated on a scheduled basis.
API credential handling
Integration credentials (OAuth tokens, API keys) provided by client organisations are stored encrypted at the application layer using AES-GCM. Raw credentials are never logged or included in error outputs. Client secrets are never exposed via any API response.
PsychFlo is built on infrastructure from established, security-certified providers:
Access to PsychFlo systems and data is controlled on a need-to-know basis:
EU data residency by default — configurable on request
All employee behavioural data is stored and processed within the EU by default. The only sub-processor outside this region is Anthropic (US), which processes anonymised, aggregated signal summaries only — no personal data is sent to the Claude API. This is covered by a Data Processing Agreement with standard contractual clauses (SCCs) under GDPR Article 46.
PsychFlo maintains comprehensive audit logs to support incident investigation and regulatory compliance:
We are committed to independent validation of our security controls:
Internal security review
In placeSecurity review of application code, API endpoints, and database access patterns is conducted by the founding team prior to each major release. OWASP Top 10 checklist applied to all new endpoints.
Third-party penetration test
ScheduledWe are scheduling a third-party penetration test with a CREST-accredited provider prior to enterprise client onboarding. Results will inform a remediation roadmap.
Ongoing vulnerability scanning
In placeDependency vulnerability scanning runs automatically via GitHub Dependabot on all production dependencies. Critical vulnerabilities trigger immediate remediation.
In the event of a security incident or suspected data breach, PsychFlo follows a documented incident response procedure:
Contain
Immediate containment of the affected system or data pathway. Affected credentials revoked within 1 hour of detection.
Assess
Assessment of scope, categories of data affected, and likely cause. Initial assessment completed within 4 hours.
Notify
Affected client organisations notified without undue delay and within 72 hours — consistent with GDPR Article 33 obligations.
Remediate
Root cause identified and remediated. Post-incident report provided to affected clients within 10 business days.
If you have identified a potential security vulnerability in PsychFlo, we ask that you contact us responsibly before public disclosure:
Security Contact
Email: info@psychflo.com
Subject: “Security Disclosure” — we will acknowledge within 24 hours and aim to remediate critical issues within 72 hours.