Security & Compliance - FAQ
Security, compliance and vendor review documentation lives in the Flagsmith Trust Centre. It is the single, current source for our certifications, reports and policies — start there for any of the questions below.
Is Flagsmith SOC 2 certified?
Yes, Flagsmith is SOC 2 Type 2 certified. Request the report through the Trust Centre.
How does Flagsmith handle GDPR and data processing agreements?
Our privacy documentation, including the DPA and the list of sub-processors, is available through the Trust Centre.
Can you complete our vendor security questionnaire?
Check the Trust Centre FAQ first — most questionnaires can be answered in full from the documentation published there, which is faster than a manual review. If something is still outstanding, contact support@flagsmith.com.
How do I report a security vulnerability?
See CVEs and Vulnerabilities for how to report an issue and the remediation SLAs we work to. Do not report vulnerabilities through public GitHub issues.
Related documentation: Help and Support
Related FAQ Categories
- Account, Billing & Organisation - Questions about accounts, SSO and billing
- Open Source & Self-Hosted - Questions about self-hosting and the Enterprise Edition