Home / Security
Trust & Compliance

Security & Data Privacy

Every conversation Floe conducts with your prospects is handled with enterprise-grade security. Prospect data stays in your control. We do not sell, share, or train on your prospect conversations.

We do not train our AI models on your customer data. Ever. Your conversations are yours.

SOC 2 Type II, In progressGDPR CompliantCCPA CompliantTLS 1.3 Encryption

Data Handling — What Floe Collects

When Floe conducts a demo with one of your prospects, it collects only what is necessary to run the demo and populate your CRM. No tracking beyond the session. No resale. No aggregation across customers.

Data collected per conversation:

  • Prospect name (if provided voluntarily during the conversation)
  • Work email address (if provided voluntarily)
  • Company name and inferred company size
  • Job role and seniority
  • Pain signals identified during discovery
  • Product areas explored during the demo
  • Full conversation transcript (stored in your Floe account, accessible to your team)
  • ICP score assigned at end of conversation

We do not collect payment information, personal financial data, health data, or any sensitive personal categories. We do not fingerprint visitors or track them across sessions on other websites.

Data Storage & Retention

All Floe data is stored on infrastructure hosted in the European Union (AWS eu-west-1) by default. Enterprise customers may request alternative data residency regions including US-East or AP-Southeast.

Retention periods:

  • Conversation transcripts: retained for 90 days by default; configurable to 30 or 365 days
  • ICP scores and lead records: retained until you delete them or deactivate your account
  • CRM integration logs: retained for 30 days for debugging purposes
  • Account data: retained for 30 days after account closure before permanent deletion

Deletion: You may request deletion of any prospect data at any time via the Floe dashboard or by emailing privacy@floe.so. Deletion requests are fulfilled within 5 business days. Data deleted from Floe is also deleted from all backup systems within 30 days.

Right to erasure (GDPR Art. 17): If a prospect contacts you to request deletion of their data, you can execute this request from within the Floe dashboard. We will confirm deletion in writing.

Your Product Data

During onboarding, you share product documentation, UI flows, and ICP criteria with Floe. This information is the knowledge base that Floe uses to run demos for your visitors.

  • Your product documentation is stored in isolated, tenant-separated storage, never combined with other customers' data
  • We do not use your product documentation to train general AI models
  • Your documentation is not shared with other Floe customers or third parties
  • If you terminate your Floe account, all ingested documentation is deleted within 30 days
  • UI flow configurations (the navigation paths Floe follows) are stored separately from product text and treated with the same isolation

Floe's access to your live product UI is scoped specifically to the pages and flows identified during onboarding. Floe does not have administrative access to your product and cannot read, modify, or export customer data held within your SaaS application.

CRM Data Flow

When a demo concludes and a lead is qualified, Floe writes structured data to your CRM (HubSpot, Salesforce, or your configured destination). Here is exactly what flows where:

Data sent to your CRM:

  • Contact record: name, email, company, role (if provided)
  • Company record: company name, inferred company size
  • Lead score / ICP score (mapped to your CRM's lead score field)
  • Demo summary: pain signals, product areas shown, key objections surfaced
  • Conversation transcript link (stored in Floe, linked from CRM record)
  • Routing assignment: which AE was notified

Data that stays in Floe:

  • Full voice conversation audio (if voice transcription is enabled)
  • Real-time scoring breakdown (detailed ICP signal analysis)
  • Session metadata (device type, time on site before demo initiation)

Floe connects to your CRM using OAuth 2.0 with scoped permissions. We request only the minimum permissions necessary to create and update contact and deal records. We do not request admin permissions or access to financial data in your CRM.

Compliance Status

Floe is designed for compliance with major data protection frameworks. The table below reflects our current status as of the last update shown at the bottom of this page.

StandardStatusTimeline / Notes
SOC 2 Type IIIn progressAudit in progress
GDPRCompliantDPA available on request; EU data residency by default
CCPACompliantData subject request process in place
HIPAA / BAAAvailable on requestBAA available for Enterprise customers in healthcare-adjacent industries
ISO 27001PlannedOn our compliance roadmap

We do not claim certifications we have not received. The SOC 2 audit is in progress, reports will be made available to customers upon completion. If your organisation requires evidence of specific controls before audit completion, contact us to discuss what we can provide.

Enterprise Security Requirements

Enterprise customers have access to additional security controls not available on Starter or Growth plans:

  • Single Sign-On (SSO): SAML 2.0 integration with your identity provider (Okta, Azure AD, Google Workspace)
  • Custom data residency: Choose between EU, US-East, and AP-Southeast data storage regions
  • Audit logs: Full access logs for all data reads, writes, and exports, exportable to your SIEM
  • IP allowlisting: Restrict Floe dashboard access to specific IP ranges
  • Business Associate Agreement (BAA): Available for organisations in healthcare-adjacent industries
  • Dedicated infrastructure: Available for organisations requiring full tenant isolation at the infrastructure level
  • Security review:We will complete your organisation's vendor security questionnaire and participate in third-party security assessments

For enterprise security onboarding, contact security@floe.so or request a security call through the book a demo page.

Infrastructure Security

  • Encryption in transit:All data transmitted between the visitor's browser, Floe's servers, and your CRM is encrypted using TLS 1.3
  • Encryption at rest: All stored data (transcripts, ICP scores, account data) is encrypted at rest using AES-256
  • Access control: Internal Floe team access to customer data is role-based and logged. Production data is accessible only to a small number of engineers for support and debugging purposes, with approval workflow
  • Vulnerability management: Regular penetration testing; critical vulnerabilities patched within 24 hours
  • Dependency scanning: Automated scanning of third-party dependencies for known CVEs
  • Incident response: Documented incident response plan; customers notified within 72 hours of any data breach affecting their account, in compliance with GDPR Art. 33
  • Subprocessors: Full list of subprocessors available on request. Material changes to subprocessors communicated with 30 days notice

Security FAQ

Who can see our data?
Your data is isolated per account and is never sold or shared with third parties. Internal access is role-based and logged — only a small number of engineers can reach production data, and only for support and debugging, through an approval workflow.
Is Floe SOC 2 certified?
SOC 2 Type II is in progress.
Can we control what Floe does?
Yes. You set the scope, the tone, and the boundaries.
Can users opt out?
Yes. Floe activates only when engaged and can be dismissed at any time.
Where is our data stored?
Data residency is configurable. Talk to us about your region requirements and we will scope hosting to fit.

Security questions?

If you are in security, compliance, legal, or procurement and have questions not answered here, we are happy to get on a call, complete a vendor questionnaire, or share additional documentation.

Last updated