Security at FiorLab

We take the security of your supplier data seriously. Here's how we protect it at every layer.

Encrypted in Transit & at Rest
EU Data Residency
Role-Based Access Control
Full Audit Trail
GDPR Compliant

Encryption

All data transmitted between your browser and FiorLab is encrypted using TLS 1.2 or higher. Data stored in our database is encrypted at rest using AES-256 encryption, managed by Google Cloud Platform's key management infrastructure. Database backups are also encrypted.

Authentication & Access Control

FiorLab uses Firebase Authentication with the following security measures:

Audit Trail

Every significant action in FiorLab is recorded in an immutable audit log, including:

Each log entry records the actor (who), action (what), timestamp (when), and full metadata. Audit logs are retained for a minimum of 7 years to meet financial services regulatory requirements.

Infrastructure & Data Residency

FiorLab runs on enterprise-grade cloud infrastructure with data stored within the European Union.

Database
Google Cloud Firestore
Authentication
Firebase Auth
Application Hosting
Vercel (EU Edge)
Data Region
EU (europe-west1)
Email Delivery
Resend (SCCs in place)
Marketing Site
Netlify (Global CDN)

Our infrastructure provider, Google Cloud Platform, maintains SOC 1/2/3, ISO 27001, ISO 27017, ISO 27018, and PCI DSS certifications.

Regulatory Compliance

FiorLab is designed to support organisations operating under:

While FiorLab itself is not yet ISO 27001 certified, we are working toward certification and our infrastructure providers hold this and other relevant certifications.

Incident Response

FiorLab maintains a documented incident response procedure:

Responsible Disclosure

If you discover a security vulnerability in FiorLab, we encourage responsible disclosure. Please report any security issues to security@fiorlab.com. We will acknowledge receipt within 24 hours and work with you to understand and resolve the issue. We will not take legal action against good-faith security researchers.

Need More Information?

For security questionnaires, DPA execution, or detailed technical questions, our team is ready to help.

Contact Security Team