Security

Security is a design constraint, not an afterthought

Fluxion Marketing is built to protect your data with layered technical and organizational safeguards, backed by independent audits.

SOC 2 Type II

Independently audited annually against the AICPA Trust Services Criteria for security, availability, and confidentiality.

Encryption everywhere

Data is encrypted in transit with TLS 1.2+ and at rest with AES-256. Encryption keys are rotated on a regular schedule.

Single sign-on

SAML- and OIDC-based SSO with SCIM provisioning, so access follows your identity provider, not a spreadsheet.

Granular access control

Role-based permissions down to the workflow level, with full audit logs of who did what and when.

Continuous monitoring

24/7 infrastructure monitoring, automated vulnerability scanning, and a dedicated on-call security response team.

Responsible disclosure

We run a private bug bounty program and welcome reports from security researchers at security@fluxion.io.

Data residency & sub-processors

Customer data is hosted in SOC 2-compliant data centers in the United States and European Union, with enterprise customers able to choose their preferred region. We maintain a public list of sub-processors and provide 30 days' notice before adding a new one, in line with our Privacy Policy.

Business continuity

Fluxion Marketing maintains geographically redundant infrastructure, automated backups, and a documented disaster recovery plan tested at least twice per year, supporting our 99.99% uptime commitment for Enterprise customers.

Need a security questionnaire or DPA?

Our team can share our SOC 2 report, penetration test summary, and standard Data Processing Agreement under NDA.