Security & Trust
Is HEFLO a Secure BPM Software?
HEFLO is a cloud-native BPM platform built on AWS with security by design. HEFLO encrypts all data with AES-256 at rest and TLS 1.2+ in transit, hosts EU customer data exclusively in Ireland for RGPD compliance, enforces MFA and RBAC, and runs annual third-party penetration tests. HEFLO operates a documented ISMS aligned with ISO/IEC 27001.

HEFLO security at a glance
The controls procurement, IT, and information security teams look for during vendor due diligence, in one view.
| Control | How HEFLO handles it |
|---|---|
| Encryption | AES-256 at rest, TLS 1.2+ in transit (2048-bit / SHA-256), keys managed with AWS KMS. |
| Data residency | EU customer data hosted exclusively in AWS Ireland (eu-west-1); São Paulo for LatAm. |
| Access control | MFA, SAML 2.0 / OIDC SSO, granular RBAC, least privilege; developers have no access to production. |
| Penetration testing | Annual independent third-party pentest; SAST/DAST in the CI/CD pipeline; summary available under NDA. |
| Availability (SLA) | Contractual SLA above 99%; multi-AZ architecture with automatic failover. |
| Disaster recovery | RTO of 2 hours, RPO of 30 minutes; recovery tested every two months. |
| Data protection (RGPD) | Article 28 DPA, Standard Contractual Clauses, appointed DPO, records of processing. |
| Subprocessors | AWS, Crisp, Google and OpenAI, covered by the DPA with change notification. |
HEFLO security, answered
Is HEFLO a secure BPM software?
Yes. HEFLO is engineered with security by design and runs on Amazon Web Services. Security is not a single feature but a documented Information Security Management System (ISMS) that governs encryption, access, hosting, resilience, and incident response across the platform. HEFLO's ISMS is maintained in alignment with ISO/IEC 27001, giving BPM teams a platform they can trust with sensitive process data.
Where is HEFLO data hosted?
HEFLO hosts data on Amazon Web Services in regional data centers. Customer data for the European Union is stored exclusively in AWS Ireland (eu-west-1), and data from EU customers never leaves the EU. Latin American customers are served from the São Paulo region. This regional isolation is what makes European data residency and RGPD compliance verifiable rather than assumed.
How does HEFLO encrypt data?
HEFLO encrypts all data at rest with AES-256 and all data in transit with TLS 1.2 or higher, using 2048-bit certificates and SHA-256. Encryption keys are managed through AWS Key Management Service (KMS). Encryption is applied by default across the platform, so process data, attachments, and forms are protected without any configuration by the customer.
How does HEFLO control access?
HEFLO enforces multi-factor authentication (MFA) and supports single sign-on through SAML 2.0 and OIDC, integrating with Azure AD, Okta, and ADFS. Access inside the platform is governed by granular role-based access control (RBAC) following the principle of least privilege. Developers do not have access to the production environment, separating who builds the platform from who can reach live customer data.
Is HEFLO GDPR (RGPD) compliant?
Yes. HEFLO supports RGPD compliance through EU data residency, an Article 28 Data Processing Agreement (DPA), Standard Contractual Clauses for any transfer, an appointed Data Protection Officer (dpo@corp.heflo.com), records of processing activities, and support for the right to erasure. These mechanisms let your legal and DPO teams document how personal data is processed and protected.
Who are HEFLO's subprocessors?
HEFLO relies on a small, documented set of subprocessors: AWS for hosting, Crisp for customer messaging, Google for supporting services, and OpenAI for optional AI features. Every subprocessor is covered by HEFLO's Data Processing Agreement, and customers are notified before any change to the list so they can assess the impact.
Does HEFLO run penetration tests and security audits?
Yes. HEFLO commissions an annual penetration test performed by an independent third party. Static and dynamic application security testing (SAST/DAST) run inside the CI/CD pipeline, and AWS GuardDuty and Inspector provide continuous threat detection. A summary of the latest penetration test is available to customers and prospects under NDA.
How reliable is HEFLO?
HEFLO operates under a contractual service-level agreement above 99% availability. The platform runs on a multi-availability-zone architecture with automatic failover, so a single point of failure does not take the service down. Live availability is published on the public status page at heflo.statuspage.io.
What is HEFLO's disaster recovery plan?
HEFLO maintains a formal disaster recovery plan with a Recovery Time Objective (RTO) of 2 hours and a Recovery Point Objective (RPO) of 30 minutes. Recovery is tested every two months to confirm those targets are met, backed by a documented Business Continuity Plan, Disaster Recovery Plan, and Business Impact Analysis.
How does HEFLO handle security incidents?
HEFLO follows a formal incident response plan. Affected customers are notified in line with RGPD requirements, and every significant event is followed by a root cause analysis and post-mortem. HEFLO has recorded zero significant security incidents over the last twelve months.
Is HEFLO ISO 27001 certified?
HEFLO is preparing its ISMS in alignment with ISO/IEC 27001. The management system already governs encryption, access control, hosting, resilience, and incident response using the ISO/IEC 27001 framework as its reference model. HEFLO does not currently claim formal certification, and this page will be updated if that status changes.
Is customer data used to train AI models?
No. HEFLO does not use customer data to train AI models. AI features follow data minimization, are optional, and can be disabled. This means teams can adopt HEFLO's AI capabilities without exposing their process data to model training.
Can HEFLO meet enterprise security requirements?
Yes. HEFLO supports SSO and SIEM integration through webhooks, log export in CSV, IP allowlisting, and customer-owned backups written to the customer's own S3 bucket. For organizations with stricter requirements, HEFLO offers private cloud and on-premises deployment options. Procurement and vendor-risk teams can request the full security package to complete their assessment.

HEFLO combines a robust, resilient architecture with verifiable data protection: AES-256 encryption, EU data residency in Ireland, an RGPD-compliant DPA, MFA and RBAC, annual third-party penetration testing, and a documented ISMS aligned with ISO/IEC 27001. It is a secure, solid foundation for running your business processes in the cloud.
Security FAQ
Yes. HEFLO is built with security by design on AWS, encrypts data with AES-256 and TLS 1.2+, enforces MFA and RBAC, and operates an ISMS aligned with ISO/IEC 27001.
HEFLO supports RGPD compliance with EU data residency in Ireland, an Article 28 DPA, Standard Contractual Clauses, an appointed DPO, and support for the right to erasure.
EU customer data is stored exclusively in AWS Ireland (eu-west-1) and never leaves the EU. Latin American customers are served from the São Paulo region.
Yes. HEFLO provides an Article 28 Data Processing Agreement covering its subprocessors, with Standard Contractual Clauses for international transfers.
HEFLO is preparing its ISMS in alignment with ISO/IEC 27001 and uses that framework as its reference model. HEFLO does not currently claim formal certification.
Yes. HEFLO enforces multi-factor authentication and supports single sign-on via SAML 2.0 and OIDC, integrating with Azure AD, Okta, and ADFS.
HEFLO operates under a contractual SLA above 99% availability, with a multi-AZ architecture and automatic failover. Live status is published at heflo.statuspage.io.
A summary of HEFLO's annual independent penetration test is available to customers and prospects under NDA. Contact the security team to request it.
No. HEFLO does not use customer data to train AI models. AI features follow data minimization, are optional, and can be disabled.
HEFLO uses AWS, Crisp, Google, and OpenAI as subprocessors, all covered by the DPA. Customers are notified before any change to the subprocessor list.
Ready to pass HEFLO through your vendor due diligence?
Request the HEFLO security package, including the DPA and the penetration test summary, or talk to our security team about your specific requirements.