Last updated:
The technical and organisational measures Spreeflo applies are set out in Annex II of our Data Processing Agreement, which forms part of every customer contract.
In summary: data is encrypted in transit with TLS 1.2 or above and at rest with AES-256; access is role-based and workspace-scoped with multi-factor authentication enforced on all administrative and infrastructure accounts; backups are automated, encrypted and periodically restore-tested; and every sub-processor is covered by written data protection terms and listed publicly at /legal/subprocessors.
To report a security issue, email security@spreeflo.com.