-
Notifications
You must be signed in to change notification settings - Fork 565
docs: add more visibility to trust.flagsmith.com #8328
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,62 @@ | ||
| --- | ||
| title: Security & Compliance - FAQ | ||
| sidebar_label: Security & Compliance | ||
| sidebar_position: 8 | ||
| description: | ||
| Flagsmith security and compliance FAQ - SOC 2 Type 2, GDPR, penetration tests, sub-processors and security | ||
| questionnaires. | ||
| keywords: | ||
| - SOC 2 | ||
| - SOC2 | ||
| - GDPR | ||
| - DPA | ||
| - penetration test | ||
| - sub-processors | ||
| - security questionnaire | ||
| - compliance | ||
| - trust centre | ||
| --- | ||
|
|
||
| import Link from '@docusaurus/Link'; | ||
|
|
||
| <span id="top" /> | ||
|
|
||
| <Link to="/support/faq">← Back to FAQ</Link> | ||
|
|
||
| <div className="faq-content"> | ||
|
|
||
| Security, compliance and vendor review documentation lives in the | ||
| **[Flagsmith Trust Centre](https://trust.flagsmith.com)**. It is the single, current source | ||
| for our certifications, reports and policies — start there for any of the questions below. | ||
|
|
||
| ### Does Flagsmith have a SOC 2 report? | ||
|
|
||
| Yes. Flagsmith has completed a SOC 2 Type 2 examination. Request the report through the | ||
| [Trust Centre](https://trust.flagsmith.com). | ||
|
|
||
| ### How does Flagsmith handle GDPR and data processing agreements? | ||
|
|
||
| Our privacy documentation, including the DPA and the list of sub-processors, is available through the | ||
| [Trust Centre](https://trust.flagsmith.com). | ||
|
|
||
| ### Can you complete our vendor security questionnaire? | ||
|
|
||
| Check the [Trust Centre FAQ](https://trust.flagsmith.com/faq#1-security-governance) first — most questionnaires can be answered in full from the | ||
| documentation published there, which is faster than a manual review. If something is still outstanding, contact | ||
| [support@flagsmith.com](mailto:support@flagsmith.com). | ||
|
|
||
| ### How do I report a security vulnerability? | ||
|
|
||
| See [CVEs and Vulnerabilities](/support/cves-and-vulnerabilities) for how to report an issue and the remediation SLAs we | ||
| work to. Do not report vulnerabilities through public GitHub issues. | ||
|
|
||
| **Related documentation:** [Help and Support](/support#security-and-compliance) | ||
|
|
||
| </div> | ||
|
|
||
| ## Related FAQ Categories | ||
|
|
||
| - [Account, Billing & Organisation](/support/faq/account-billing-organisation) - Questions about accounts, SSO and | ||
| billing | ||
| - [Open Source & Self-Hosted](/support/faq/open-source-self-hosted) - Questions about self-hosting and the Enterprise | ||
| Edition | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -80,7 +80,23 @@ depending on your issue type. | |
| - **In-app chat** - Click the support widget in the Flagsmith dashboard | ||
| - **Email** - [support@flagsmith.com](mailto:support@flagsmith.com) | ||
| - **Community** - [Discord](https://discord.gg/hFhxNtXzgm) | ||
| - **Trust Centre** - [trust.flagsmith.com](https://trust.flagsmith.com) | ||
|
|
||
| ### Security and Compliance | ||
|
|
||
| Security questionnaires, compliance documentation and our SOC 2 Type 2 report start at the | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. This doesn't really make sense - I'm not sure why the change was necessary? The SOC 2 Type 2 report for example is categorically available on the trust centre so 'start at' doesn't make sense in that context. In my opinion, we should go back to what you had before. We can still add the fallback to support@flagsmith.com either way. People are still going to use that bail out regardless of whether we give it to them or not tbh! |
||
| **[Flagsmith Trust Centre](https://trust.flagsmith.com)** rather than the support channels above. Go there to: | ||
|
|
||
| - Review our security posture, certifications and sub-processors | ||
| - Request access to compliance reports and policies | ||
| - Complete or shortcut a vendor security review | ||
|
|
||
| If your questionnaire still has outstanding items once you have checked the Trust Centre, email | ||
| [support@flagsmith.com](mailto:support@flagsmith.com) with the specific questions that remain. | ||
|
|
||
| Common questions about SOC 2, GDPR and vendor security reviews are answered in the | ||
| [Security & Compliance FAQ](/support/faq/security-compliance). | ||
|
|
||
| To report a security vulnerability, see [CVEs and Vulnerabilities](./cves-and-vulnerabilities.md). | ||
|
coderabbitai[bot] marked this conversation as resolved.
|
||
|
|
||
| ### Enterprise Support | ||
|
|
||
|
|
||
Uh oh!
There was an error while loading. Please reload this page.