How We Protect Your Data
Encryption, security measures, and compliance
Our Commitment to Security
At AskFLC, protecting your data is our top priority. We implement industry-leading security measures, encryption standards, and compliance protocols to ensure your conversations, personal information, and uploaded files remain secure and private.
Multi-Layer Security Architecture
End-to-End Encryption
All data transmitted between your device and our servers is encrypted using industry-standard TLS 1.3 encryption protocol.
What this means for you:
- Your conversations are encrypted in transit
- Nobody can intercept or read your messages
- Bank-level security for all communications
Secure Data Storage
Your data is stored in encrypted form on secure cloud infrastructure with multiple redundancy layers to prevent loss.
Storage security features:
- AES-256 encryption at rest
- Regular automated backups
- Geographically distributed data centers
- 24/7 infrastructure monitoring
Authentication & Access Control
How We Verify Your Identity:
Secure Authentication
We use secure OAuth 2.0 protocols for login, supporting multiple authentication providers (Google, Apple, email) to ensure only you can access your account.
Password Protection
Passwords are hashed using bcrypt with salt, making them virtually impossible to decrypt even in the unlikely event of a data breach.
Session Management
Secure session tokens expire after periods of inactivity, and you can remotely log out from all devices at any time.
Two-Factor Authentication (Coming Soon)
We're adding optional 2FA for an extra layer of security, requiring both your password and a verification code to log in.
File Upload Security
Protecting Your Documents
When you upload files (Premium+ feature), we take special measures to protect your documents:
Virus Scanning: All uploaded files are automatically scanned for malware and viruses before processing
File Type Validation: We verify file types to prevent malicious uploads
Secure Processing: Files are processed in isolated environments to prevent cross-contamination
Automatic Deletion: Temporary processing files are automatically deleted after analysis
Access Restrictions: Only you can access your uploaded files - not even our staff can view them without explicit permission
Compliance & Certifications
GDPR Compliant
We comply with the European Union's General Data Protection Regulation, ensuring:
- Right to access your data
- Right to data portability
- Right to be forgotten
- Transparent data practices
CCPA Compliant
California Consumer Privacy Act compliance provides California residents with:
- Know what data we collect
- Delete personal information
- Opt-out of data sales (we don't sell data)
- Non-discrimination rights
SOC 2 Type II
Our infrastructure undergoes annual third-party audits for:
- Security controls
- Availability standards
- Confidentiality measures
- Privacy protections
HIPAA Considerations
While not a covered entity, we follow HIPAA-aligned practices:
- Encrypted data transmission
- Access controls and audit logs
- Secure data storage
- Staff security training
Internal Security Practices
Employee Access Controls
Our employees have limited access to user data based on their role. Access is logged and regularly audited. We never access your conversations without explicit consent for support purposes.
Security Training
All team members undergo comprehensive security training and sign confidentiality agreements. We maintain a culture of security awareness.
Regular Security Audits
We conduct quarterly internal security audits and annual third-party penetration testing to identify and address vulnerabilities.
Incident Response Plan
We maintain a comprehensive incident response plan and will notify affected users within 72 hours of discovering any security breach.
Third-Party Services
Vetted Security Partners
We carefully select third-party services that meet our high security standards:
Cloud Infrastructure
Hosted on enterprise-grade cloud platforms (AWS/GCP) with SOC 2 Type II certification and 99.99% uptime SLA
Payment Processing
PCI DSS Level 1 compliant payment processors. We never store your complete credit card numbers
Analytics
Privacy-focused analytics that don't track individual users or share data with advertisers
What We Don't Do
Our Privacy Commitments:
We never sell your data to third parties, advertisers, or data brokers
We don't use your conversations to train AI models without explicit opt-in consent
We don't share personal information with insurance companies or agents without your explicit consent
We don't track you across other websites or apps
We don't require unnecessary permissions on your device beyond what's needed for core functionality
Reporting Security Issues
Found a Vulnerability?
We take security reports seriously and appreciate responsible disclosure. If you discover a security vulnerability:
Contact our security team:
Email: security@askflc.com
Please provide detailed information about the vulnerability and steps to reproduce it. We'll respond within 48 hours and work with you to address the issue.
Your Role in Security
While we implement robust security measures, you also play a crucial role in protecting your account:
- Use a strong, unique password for your AskFLC account
- Never share your login credentials with others
- Log out when using shared or public computers
- Be cautious about what personal information you share in conversations
- Report suspicious activity to our support team immediately
Learn more in our Account Security Best Practices guide.