Skip to main content

Security & Compliance - FAQ

← Back to FAQ

Security, compliance and vendor review documentation lives in the Flagsmith Trust Centre. It is the single, current source for our certifications, reports and policies — start there for any of the questions below.

Is Flagsmith SOC 2 certified?

Yes, Flagsmith is SOC 2 Type 2 certified. Request the report through the Trust Centre.

How does Flagsmith handle GDPR and data processing agreements?

Our privacy documentation, including the DPA and the list of sub-processors, is available through the Trust Centre.

Can you complete our vendor security questionnaire?

Check the Trust Centre FAQ first — most questionnaires can be answered in full from the documentation published there, which is faster than a manual review. If something is still outstanding, contact support@flagsmith.com.

How do I report a security vulnerability?

See CVEs and Vulnerabilities for how to report an issue and the remediation SLAs we work to. Do not report vulnerabilities through public GitHub issues.

Related documentation: Help and Support