Trust Center

Security and Compliance You Can Verify

Flentas runs client data and infrastructure to independently audited standards. Here is how we protect what you entrust to us, the certifications behind it, and what that means for your business.

Certifications & Partnerships

Independently Verified

ISO 27001 Certified

ISO 27001

A certified information security management system covering how we handle client data, access and risk.

AICPA SOC 2 Badge

SOC 2 Type II

Independently audited to the AICPA SOC 2 Type II standard: our security, availability and confidentiality controls are tested in operation over months, not checked on a single day.

AWS Premier Tier Services

AWS Premier Tier Services Partner

AWS's highest partner tier, earned through audited delivery capability and verified customer outcomes.

AWS Advanced Consulting Partner

AWS Advanced Consulting Partner

A validated AWS consulting practice with certified engineers and reviewed customer engagements.

Great Place to Work Certified (GPTW)

Great Place to Work Certified

Retained, accountable engineers are part of operational security; a certified workplace keeps them.

How We Protect You

Data and Infrastructure Security, Built In

Security is not a phase at the end of an engagement. These are the controls that apply to every environment we build, migrate or operate.

  • Least-Privilege Access

    Role-based access, multi-factor authentication and just-in-time elevation on every client environment. Access is reviewed on a schedule and revoked when an engagement ends.

  • Encryption Everywhere

    Data is encrypted in transit and at rest, with customer-managed keys where you need them. Secrets live in a vault, never in code, tickets or chat.

  • Secure Delivery Pipeline

    Peer review, automated security scanning and change control gate every release before it reaches your production accounts.

  • Monitoring and Incident Response

    Centralised logging, alerting and a tested incident process with defined notification timelines, so you hear from us first.

  • Vendor and Sub-processor Governance

    Every tool that touches client data is assessed, listed in our privacy policy and covered by data-processing terms.

  • Resilience and Recovery

    Backups, documented recovery objectives and regular restore tests, so an outage is an event rather than a crisis.

What It Means for You

Value Beyond the Certificate

  • Faster Vendor Approval

    Audit reports, policies and completed questionnaires are ready to share, so security reviews and procurement move in days rather than months.

  • Confidence in Regulated Industries

    Controls mapped to the frameworks your regulators and customers ask about, from ISO 27001 to sector rules in finance and healthcare.

  • Fewer Surprises in Production

    Security is designed into every migration, modernisation and AI engagement from the first assessment, not bolted on at go-live.

Security Documentation

Need Our Security Documentation?

Request our ISO 27001 certificate, SOC 2 report or a completed security questionnaire, or talk to us about your compliance requirements.