Compliance
Overview of Flank's security and compliance frameworks.

ISO 42001
Global standard for the responsible and ethical management of Artificial Intelligence (AI).

SOC 2 Type 2
Audit certifying the continuous operational effectiveness of security controls.

GDPR
EU regulation governing the protection and processing of personal data.

CCPA
California law granting consumers control over their personal data, including the right to opt out of its sale or sharing.
Resources
Flank's certifications, audit reports, and accreditation documents.
SOC 2 Type 2 – Report
The SOC 2 Type 2 Report provides independent validation of the design and operating effectiveness of Flank’s security controls over a continuous period. This report confirms our sustained commitment to protecting your data.
ISO 42001 – Certificate
The ISO 42001 Certification validates that Flank implements a robust Artificial Intelligence Management System (AIMS). This framework ensures the responsible, ethical, and transparent development and deployment of our AI features, providing governance over related legal, safety, and fairness considerations. AIMS-LE-103025
How Flank uses LLMs – FAQ
Our LLM FAQ provides complete transparency into our use of Large Language Models (LLMs). This document details our data handling practices, security controls around prompt injection, assurances on whether customer data is used for model training, and our guidelines for ethical AI usage.
Data Processing Agreement
The Data Processing Agreement (DPA) is our contractual commitment to meet stringent global data protection regulations, including the GDPR and CCPA. It legally outlines our roles and responsibilities as a Data Processor to ensure the confidentiality, integrity, and lawful handling of your end-user personal data.
Subprocessors
Google Cloud
Cloud computing, LLMs

Anthropic
LLMs

OpenAI
LLMs

Mailgun
Email sending service
MongoDB
Database
Azure
LLMs
