FlexPortal

Security & Compliance

Choose where your data lives. EU, US, or custom regions with encryption and access controls built in.

Choose your data region

Your data stays where you need it. No cross-region transfers.

🇪🇺

European Union

Frankfurt, Germany

  • GDPR compliant
  • Data never leaves EU
  • Optimized for European teams
🇺🇸

United States

Iowa, USA

  • US data residency
  • Data never leaves US
  • Optimized for US teams
🌍

Custom Region

Enterprise only

  • Country-specific deployment
  • Dedicated infrastructure
  • Contact us to discuss

Encrypted everywhere

At rest

AES-256 encryption (Google Cloud default)

In transit

TLS 1.2+ for all connections

Backups

Encrypted and stored in-region

Built on Google Cloud Platform

Database Regional database with data isolation
Compute Regional Cloud Functions
Secrets Google Secret Manager
Monitoring Regional logging and error tracking

Granular permissions

Role-based access

Define custom roles with specific permissions

Module-level control

Set read/write access per module per user

Multi-Factor Authentication

MFA available for all users

Single Sign-On

SSO for Enterprise plans

Compliance-ready infrastructure

GDPR

  • EU data region available
  • Data Processing Agreement (DPA) available for Enterprise
  • Data export and deletion capabilities

HIPAA-Ready Infrastructure

  • Regional data storage
  • Encryption at rest and in transit
  • Access controls and audit logging

FlexPortal's infrastructure supports HIPAA compliance requirements. For healthcare deployments, contact us to discuss your specific needs.

Enterprise-grade security

Additional security features for Enterprise plans.

SSO SAML-based single sign-on
SLAs Uptime guarantees and response time commitments
DPA Custom Data Processing Agreement
Security review Dedicated security questionnaire process
Custom residency Deployments for specific data residency requirements

See also: Features · FAQ · Integrations

Questions about security?

Enterprise customers can request a security review and discuss specific compliance requirements.