Security

Your customers, your orders, your money โ€” locked down.

PCI DSS Level 1. SOC 2 Type II. HIPAA available on Enterprise. A public trust portal so you don't have to take our word for it.

Last updated ยท May 14, 2026

Certifications & attestations

  • PCI DSS Level 1

    Audited annually. Zero exceptions on our most recent report.

  • SOC 2 Type II

    Continuous attestation across security, availability, confidentiality.

  • GDPR / UK-GDPR

    EU + UK data residency. DPAs available on every plan.

  • HIPAA

    Available on Enterprise. BAA executed at signing.

Card data & tokenization

We never see raw card data. PANs are tokenized inside a hosted iframe sandboxed from your storefront's JavaScript. Tokens are scoped per processor and per merchant ID โ€” a token issued for one processor cannot be replayed on another.

3DS2 is applied automatically based on issuer signals and our risk model. Step-up is invisible to ~94% of shoppers; the other 6% see a one-tap challenge.

Infrastructure

  • AWS us-east-1, eu-west-1, ap-southeast-1 โ€” single-tenant VPCs per Enterprise customer if required.
  • All data encrypted at rest (AES-256) and in transit (TLS 1.3 minimum).
  • Per-tenant KMS keys. You can revoke at any time; we lose access immediately.
  • 99.99% uptime SLA on Enterprise. Status page at status.growthflowline.com.
  • Hot standby in a second region. RPO โ‰ค 30s, RTO โ‰ค 5m.

Access control

SSO via SAML 2.0 + SCIM provisioning on Pro and Enterprise. Audit logs are append-only and retained 90 days (Pro) or indefinitely (Enterprise). Every workspace ships with role-based access controls โ€” Admin, Operator, Finance, Support, Read-only โ€” and you can define custom roles.

Vulnerability disclosure

Security researchers โ€” please email security@growthflowline.com. We respond within one business day, scope and reward via our private HackerOne program. Safe-harbor terms apply for good-faith research.

The trust portal

Our public trust portal hosts our SOC 2 report, PCI AOC, pen-test summaries, sub-processor list, and the current security questionnaire pre-filled. No NDA required for the summaries. Full reports under NDA โ€” request access in one click.

Open trust portal
Talk to sales

The platform your DTC brand deserves.

Replace your checkout, payments, CRM, and subscription apps with one platform. Migrate in a weekend.

20-min call Weekend migration Real operators