Skip to content
fyltfylt
FeaturesPricingContact UsKnowledge base

Data Security

Version 1.1 - Last updated July 31, 2026

Service businesses trust fylt with client relationships, contracts, and payment records. This page describes the technical and organizational measures that help protect that data and complements our Privacy Policy.

Encryption everywhere

Traffic to and from fylt is protected with TLS 1.2+. Data at rest, including our primary database and object storage, uses provider-managed encryption keys.

Per-app session isolation

Marketing, Studio, Workspace, and Admin each use a session cookie scoped to that product surface, helping keep every experience appropriately separated.

Access controls & MFA

Admin access is role-based across superadmin, ops, support, finance, and content roles, with multi-factor authentication and an auditable record of administrative actions.

Hardened infrastructure

The Service uses isolated network segments and least-privilege access between the API, orchestrator, database, cache, and object-storage tiers.

Secure development lifecycle

Dependencies are scanned for known vulnerabilities, changes go through code review, and secrets are never committed to source control.

Backups & disaster recovery

Databases are backed up on a recurring schedule with point-in-time recovery, and backup restoration is periodically tested.

Incident Response

fylt maintains a documented incident-response process covering detection, containment, recovery, and post-incident review. For a confirmed personal-data breach, we notify affected customers and applicable regulators within the timeframes required by applicable law.

AI-Assisted Workflows

fylt AI is designed to create a draft for your review inside the workflow where you requested it. Requests are sent through protected service-to-service connections to our configured AI service provider and use the business context you choose to include. Customers remain in control of reviewing, refining, and sharing every draft.

Responsible Disclosure

If you believe you have found a security vulnerability in the Service, please report it to security@fylt.app. We ask that you give us a reasonable opportunity to investigate and remediate an issue before any public disclosure, and we commit to acknowledging reports within two (2) business days.

Sub-processors

fylt uses a limited set of sub-processors to operate the Service, including our cloud infrastructure and object storage provider, our subscription payments processor (Razorpay), and our transactional email provider. Each sub-processor is bound by a data-processing agreement consistent with our Privacy Policy. A current list is available on request at privacy@fylt.app.

Compliance Certifications

Our security program is aligned with SOC 2 Trust Services Criteria and a formal audit is in progress. See our Compliance page for current certification status and regulatory alignment, including GDPR and CCPA/CPRA.

fylt

AI-powered client operations for independent professionals and service businesses. One connected platform for every stage of the client journey.

hello@fylt.app

fylt

  • Features
  • Pricing
  • Knowledge base
  • Storefront

Company

  • About fylt
  • Why use fylt
  • Contact Us
  • Studio Login

Legal

  • Terms of Service
  • Privacy Policy
  • Data Security
  • Compliance
GDPR-ready data handling TLS-encrypted in transit SOC 2 program in progress
© 2026 fylt, Inc. All rights reserved.Sitemap