Security & Compliance
Your Data, Locked Down
Finance teams trust Fluxity with sensitive documents every day. We built our security architecture to earn that trust — not just claim it.
ARCHITECTURE
How We Protect Your Data
Encryption
Designed for AES-256 encryption at rest and TLS 1.3 in transit. Documents are encrypted from the moment they leave your browser.
Access Control
Role-based access control with least-privilege defaults. Built to support SSO and SAML for enterprise identity management.
Audit Logging
Every document interaction is logged — who accessed what, when, and what changed. Audit trails are designed to be immutable and exportable.
Data Isolation
Tenant data is logically separated with strict access boundaries. Our architecture prevents cross-tenant data access.
Infrastructure
Cloud infrastructure designed to align with SOC 2 requirements — encrypted backups, network segmentation, and monitoring.
Data Retention
Configurable retention policies to meet your compliance requirements. Secure deletion procedures when data is no longer needed.
ERP CONNECTIONS
Secure by Design, Connected by Default
Fluxity integrates with your ERP without compromising your security posture. Every connection is scoped, audited, and transparent.
Read-only by default
Fluxity is designed to read from your ERP for validation — write access is opt-in and scoped to specific record types.
Scoped credentials
Each ERP connection is designed to use dedicated, least-privilege API keys — no admin-level access required.
Credential protection
ERP credentials are encrypted and never stored in plaintext. OAuth-based connections support automatic token rotation.
Transparent permissions
Before connecting, you can review exactly what Fluxity will access. No hidden scopes, no silent escalation.
COMPLIANCE
Our Compliance Journey
We're building Fluxity with enterprise-grade security from day one. Here's where we are and where we're headed.
SOC 2 Type II
In ProgressDesigning controls and preparing for formal audit
GDPR-aligned data handling
In ProgressBuilding toward data minimization, erasure, and processing records
Penetration testing
CommittedThird-party security assessments planned
Incident response plan
In ProgressDocumenting procedures and response SLAs
Have Security Questions?
Our team is happy to walk through our security practices during your demo.