Security and trust
Clear controls. Honest status.
Last reviewed July 21, 2026
FLADA is designed around separate company workspaces and individual employee identities. This page describes controls present in the product architecture and clearly separates them from certifications not yet earned.
Account protection
FLADA uses individually authenticated user accounts, hashed passwords, signed access tokens, verification flows, rate limiting, and account-lockout controls. Mobile credentials are stored using the operating system’s secure storage facilities.
Workspace isolation
Customer, deal, task, calendar, and activity records are scoped to their company organization. Authorization checks are applied to prevent one organization from reading or modifying another organization’s data.
Payments
Subscription checkout is handled by Stripe. FLADA does not directly store full payment-card details. Production payment processing depends on the deployed Stripe configuration and completed launch review.
Operational safeguards
The backend applies security headers, request-size limits, validation, rate limits, structured logging, and controlled file-upload paths. Production deployment, backup, recovery, monitoring, and incident-response procedures must be verified before general availability.
Compliance status
FLADA is not currently represented as SOC 2, ISO 27001, HIPAA, PCI DSS, or ADA certified. PCI responsibilities for card processing are primarily handled through Stripe’s hosted checkout, but FLADA’s own scope must still be confirmed. Certification badges will not appear until evidence and an appropriate independent assessment exist.
Report a concern
Send security concerns to hello@flada.io. Do not include passwords, access tokens, or live customer data in the initial message.