Security & Trust
Is HEFLO a Secure BPM Software?
HEFLO is a cloud-native BPM platform built on AWS, where security is part of the architecture, not a layer added later. This page documents how that works: where your data lives, who can reach it, and what happens when something goes wrong.
Four figures that describe the platform your processes would run on, taken from the production infrastructure itself.
3
availability zones behind every production database
35 days
of point-in-time database recovery
0
public IP addresses on application servers
99%+
contractual availability SLA
HEFLO security at a glance
The controls procurement, IT, and information security teams look for during vendor due diligence, in one view.
| Control | How HEFLO handles it |
|---|---|
| Encryption | AES-256 at rest, TLS 1.2+ in transit (2048-bit / SHA-256), keys managed with AWS KMS. |
| Data residency | Process data and backups stay in the customer's region: EU in AWS Ireland (eu-west-1), backups in Frankfurt; LatAm in São Paulo. Account, search and telemetry services process data in other regions under Standard Contractual Clauses. |
| Network architecture | Application servers run in private subnets with no public IP; traffic reaches them only through CloudFront and a WAF, never directly. |
| Access control | MFA, SAML 2.0 / OIDC SSO, granular RBAC, least privilege; developers have no access to production. |
| Penetration testing | Regular independent third-party penetration testing; SAST/DAST in the CI/CD pipeline; summary available under NDA. |
| Availability (SLA) | Contractual SLA above 99%; multi-AZ architecture with automatic failover. |
| Backup and recovery | Daily Aurora backups with 35-day point-in-time recovery; cross-region copies to a locked vault, kept inside the EU for European data. |
| Data protection (RGPD) | Article 28 DPA, Standard Contractual Clauses, appointed DPO, records of processing. |
| Subprocessors | AWS, Crisp, Google and OpenAI, covered by the DPA with change notification. |
Architecture and network
How is HEFLO's network protected from the internet?
HEFLO's application servers are not reachable from the internet. They run in private subnets with no public IP address, behind internal load balancers, so there is no address an attacker can connect to directly. All traffic arrives through Amazon CloudFront, where a web application firewall inspects and filters requests before they reach the application, and TLS 1.2 is enforced as the minimum protocol version. This matters because most successful attacks on cloud applications do not defeat encryption. They find an exposed management port, an unprotected load balancer, or a forgotten test server. Removing the public attack surface eliminates that class of risk instead of trying to defend against it.
How does HEFLO encrypt data?
HEFLO encrypts all data at rest with AES-256 and all data in transit with TLS 1.2 or higher, using 2048-bit certificates and SHA-256. Encryption keys are managed through AWS Key Management Service (KMS). Encryption is applied by default across the platform, so process data, attachments, and forms are protected without any configuration by the customer.
How does HEFLO control access?
HEFLO enforces multi-factor authentication (MFA) and supports single sign-on through SAML 2.0 and OIDC, integrating with Azure AD, Okta, and ADFS. Access inside the platform is governed by granular role-based access control (RBAC) following the principle of least privilege. Developers do not have access to the production environment, separating who builds the platform from who can reach live customer data.
Data residency and backups
Where is HEFLO data hosted?
HEFLO hosts data on Amazon Web Services in regional data centers. Your process data (the models, forms, documents and attachments your teams work with, plus the database that stores them) is held in your region: AWS Ireland (eu-west-1) for the European Union, São Paulo for Latin America. The isolation goes beyond the database. Application, data and reporting services are deployed independently in each region, so process execution happens where the data lives and is not routed back to a central location. Backups follow the same rule: EU recovery points are copied to Frankfurt and stay inside the EU. A defined set of supporting services (account and sign-in, e-mail delivery, search indexing, AI features and telemetry) runs from other AWS regions, so a limited amount of data is processed outside your region under Standard Contractual Clauses. The transfer question below has the full picture.
How does HEFLO back up and recover data?
HEFLO protects data at three levels. Within the region, the database layer is replicated across three separate availability zones, so losing one zone does not mean losing the service or your data. Aurora takes daily backups with point-in-time recovery over a 35-day window, letting a database be restored to a specific moment rather than only to the last snapshot. Beyond that, AWS Backup copies recovery points to a second region every day, into a locked vault that protects them from accidental or malicious deletion. For European customers those copies go from Ireland to Frankfurt, so backups never leave the EU. Your process data and its backups are held to the same regional rule, which is where many cloud platforms quietly break their own promise. A business continuity plan built on this backup architecture is currently being implemented; customers who need formal recovery objectives can request its current status from the security team.
Can I keep my own copy of my data?
Yes, every customer can. Beyond HEFLO's own backups, you can enable a continuous data stream that consolidates your Aurora and DynamoDB data into a dedicated relational (MySQL) database for your environment. Use it to build your own BI and reporting, keep it as an independent backup, or have HEFLO push a daily export straight to your own Amazon S3 bucket, using your own API key. A full, ready-to-import MySQL copy of your process data lands in infrastructure you control, every day. The replica is encrypted and not publicly accessible, and for European customers it stays in the EU, in line with data residency. It is the direct answer to lock-in: your data is never trapped inside HEFLO.
Availability and incident response
How reliable is HEFLO?
HEFLO operates under a contractual service-level agreement above 99% availability. The platform runs on a multi-availability-zone architecture with automatic failover, so a single point of failure does not take the service down. Live availability is published on the public status page at heflo.statuspage.io.
How does HEFLO handle security incidents?
HEFLO follows a formal incident response plan. Affected customers are notified in line with RGPD requirements, and every significant event is followed by a root cause analysis and post-mortem. HEFLO has recorded zero significant security incidents over the last twelve months.
Compliance and governance
How does HEFLO monitor for vulnerabilities?
Static and dynamic application security testing (SAST/DAST) run inside the CI/CD pipeline, so code is checked for vulnerabilities before it ships. In production, Amazon Inspector continuously scans HEFLO's compute layer (servers, containers, and serverless functions) for known vulnerabilities, a web application firewall filters traffic at the edge, and all administrative activity is recorded in AWS CloudTrail.
Does an independent third party test HEFLO's security?
Yes. HEFLO commissions penetration tests carried out by an independent security firm that is paid to break in, not HEFLO's own team. This is adversarial testing by people with no incentive to find the platform secure, and it is what separates a real security posture from a self-assessment. A summary of the most recent test is available to customers and prospects under NDA, so your security team can read the findings for themselves.
Is HEFLO GDPR (RGPD) compliant?
Yes. HEFLO supports RGPD compliance through EU data residency, an Article 28 Data Processing Agreement (DPA), Standard Contractual Clauses for any transfer, an appointed Data Protection Officer (dpo@corp.heflo.com), records of processing activities, and support for the right to erasure. These mechanisms let your legal and DPO teams document how personal data is processed and protected.
Does HEFLO transfer personal data outside my region?
Yes, for a defined and limited set of supporting services, and each one is documented. Your process data (models, forms, documents, attachments, the database and its backups) stays in your region. What is processed elsewhere is: account and sign-in data, replicated between regions so your users can sign in from anywhere and so the service survives the loss of a region; e-mail delivery; search indexing; optional AI features, which receive process documentation and automation settings and no personal data; and operational telemetry such as logs, metrics and traces, kept for a short retention period. Every one of these transfers is covered by HEFLO's Data Processing Agreement and Standard Contractual Clauses, and is listed in HEFLO's records of processing activities, which your DPO can request. If your organisation requires strict single-region processing, HEFLO offers private cloud and on-premises deployment.
Who are HEFLO's subprocessors?
HEFLO relies on a small, documented set of subprocessors: AWS for hosting, Crisp for customer messaging, Google for supporting services, and OpenAI for optional AI features. Every subprocessor is covered by HEFLO's Data Processing Agreement, and customers are notified before any change to the list so they can assess the impact.
Is HEFLO ISO 27001 certified?
HEFLO is preparing its ISMS in alignment with ISO/IEC 27001. The management system already governs encryption, access control, hosting, resilience, and incident response using the ISO/IEC 27001 framework as its reference model. HEFLO does not currently claim formal certification, and this page will be updated if that status changes.
Is customer data used to train AI models?
No. HEFLO does not use customer data to train AI models. AI features follow data minimization, are optional, and can be disabled. This means teams can adopt HEFLO's AI capabilities without exposing their process data to model training.
Can HEFLO meet enterprise security requirements?
Yes. HEFLO supports SSO and SIEM integration through webhooks, log export in CSV, IP allowlisting, and customer-owned backups written to the customer's own S3 bucket. For organizations with stricter requirements, HEFLO offers private cloud and on-premises deployment options. Procurement and vendor-risk teams can request the full security package to complete their assessment.
What this adds up to
Security by design
Built into the architecture, not bolted on afterwards.
Your data, isolated and encrypted
Protected at rest and in transit, by default, with no setup.
Data that stays where you expect
Your process data and its backups are held in your region, and transfers are documented.
Open to inspection
Ask our security team for the evidence behind any statement here. That is what it is for.
Ready to pass HEFLO through your vendor due diligence?
Request the HEFLO security package, including the DPA and the penetration test summary, or talk to our security team about your specific requirements.