Skip to content
fylt
PricingContact UsKnowledge base

Data Security

Version 1.1 - Last updated July 31, 2026

Service businesses trust fylt with client relationships, contracts, and payment records. This page describes the technical and organizational measures that help protect that data and complements our Privacy Policy.

Quick answer: how does fylt secure data?

This page explains how fylt protects client and customer data: TLS encryption in transit, encrypted storage at rest, role-based admin access with required multi-factor authentication, isolated sessions per app, hardened infrastructure, a documented incident-response process, regular backups, and a security program aligned with SOC 2 Trust Services Criteria for Security, Availability, and Confidentiality. SOC 2 audit in progress; fylt is not yet SOC 2 certified.

Encryption everywhere

Traffic to and from fylt is protected with TLS 1.2+. Data at rest, including our primary database and object storage, uses provider-managed encryption keys.

Per-app session isolation

Marketing, Studio, Workspace, and Admin each use a session cookie scoped to that product surface, helping keep every experience appropriately separated.

Access controls & two-factor authentication

Admin access is role-based across superadmin, ops, support, finance, and content roles, with an auditable record of administrative actions. MFA is required for administrative access. Two-factor authentication is available for customer accounts.

Hardened infrastructure

The Service uses isolated network segments and least-privilege access between the API, orchestrator, database, cache, and object-storage tiers.

Secure development lifecycle

Dependencies are scanned for known vulnerabilities, changes go through code review, and secrets are never committed to source control.

Backups & disaster recovery

Databases are backed up on a recurring schedule with point-in-time recovery, and backup restoration is periodically tested.

Incident Response

fylt maintains a documented incident-response process covering detection, containment, recovery, and post-incident review. For a confirmed personal-data breach, we notify affected customers and applicable regulators within the timeframes required by applicable law.

AI-Assisted Workflows

fylt AI is designed to create a draft for your review inside the workflow where you requested it. Requests are sent through protected service-to-service connections to our configured AI service provider and use the business context you choose to include. Customers remain in control of reviewing, refining, and sharing every draft.

Responsible Disclosure

If you believe you have found a security vulnerability in the Service, please report it to security@fylt.app. We ask that you give us a reasonable opportunity to investigate and remediate an issue before any public disclosure, and we commit to acknowledging reports within two (2) business days.

Sub-processors

fylt uses a limited set of sub-processors to operate the Service, including our cloud infrastructure and object storage provider, our subscription payments processor (Razorpay), our transactional email provider, and — only for the optional paid-booking feature, where a business collects a specific booking payment from its own client through fylt — Razorpay or PayPal as the payment sub-processor for that transaction. fylt Billing invoices and the Workspace client portal are record-keeping only and never route a client payment through fylt. Each sub-processor is bound by a data-processing agreement consistent with our Privacy Policy. A current list is available on request at privacy@fylt.app.

Compliance Alignment

Our security program is aligned with the SOC 2 Trust Services Criteria for Security, Availability, and Confidentiality. A formal third-party audit is in progress, and fylt is not yet SOC 2 certified. See our Compliance page for full details on regulatory alignment, including GDPR and CCPA/CPRA.

Frequently Asked Questions

Traffic to and from fylt is protected with TLS 1.2+, and data at rest — including the primary database and object storage — uses provider-managed encryption keys.

Yes. Marketing, Studio, Workspace, and Admin each use a session cookie scoped to that specific product surface, keeping the experiences appropriately isolated.

MFA is required for administrative access. Two-factor authentication is available for customer accounts.

fylt maintains a documented incident-response process and a responsible-disclosure channel at security@fylt.app, with reports acknowledged within two business days.

SOC 2 audit in progress. fylt's security program is aligned with SOC 2 Trust Services Criteria — see the Compliance page for the latest status. fylt is not SOC 2 certified.

fylt

Connected client operations workspace for independent professionals and service businesses. One connected loop for every stage of the client journey.

hello@fylt.app

Solutions For

  • Interior Design
  • Consultants
  • Legal Practice
  • Boutique Agencies
  • Creative Studios
  • Enterprise

Product

  • Features
  • Pricing
  • Templates
  • Free Tools
  • Storefront
  • Help Center

Company

  • About Us
  • Why fylt
  • Contact
  • Connected vs. Point Solutions
  • The Sync Engine

Blog

  • Retainer Pricing for Consultants and Agencies: A Setup Guide That Doesn't Fall Apart
  • The Death of SaaS Sprawl: Why Modern Agencies Are Switching to Connected Client Operations
  • How to Onboard a New Client Without Losing the First Two Weeks
  • What a Branded Client Portal Actually Changes About How Clients See You
  • How Do I Get Clients to Pay Invoices On Time?

Legal

  • Terms
  • Privacy
  • Refund Policy
  • Data Security
  • Compliance
Privacy practices designed to support GDPR TLS encryption in transit SOC 2 Trust Services Criteria aligned
© 2026 Luna Exim, Inc. All rights reserved.Sitemap