Your fabrication data is the backbone of your business — and we treat it that way. FabFlow is built from the ground up with enterprise-grade security to protect your shop floor data, customer records, and intellectual property. Here’s how we keep your data safe.
Encryption Everywhere
All data is encrypted at rest using AES-256 and in transit via TLS 1.3. Database volumes, backups, and file attachments are fully encrypted.
SOC 2 Compliance
FabFlow maintains SOC 2 Type II certification, independently audited annually. Our controls meet the highest standards for security, availability, and confidentiality.
Automated Backups
Continuous point-in-time recovery with hourly incremental backups and daily full snapshots retained for 90 days. All backups are encrypted and geo-redundant.
RBAC & Access Control
Role-based access control lets you define exactly who sees what — from shop floor operators to shop owners. Granular permissions per module.
SOC 2 Type II Certified
FabFlow has achieved SOC 2 Type II certification, which means an independent auditor has verified that our security controls are not only properly designed but also operating effectively over an extended period. Our SOC 2 report covers the Trust Services Criteria for Security, Availability, and Confidentiality. We undergo annual re-certification, and the latest report is available to enterprise customers under NDA.
Our SOC 2 controls include: continuous vulnerability scanning, formal change management procedures, incident response protocols, background checks for all personnel, mandatory security training, and quarterly access reviews. Every control is monitored, tested, and documented.
Encryption Standards
We don’t cut corners on cryptography. All customer data is protected with AES-256 encryption at rest — this covers our primary databases, file storage, search indexes, and all backup volumes. Data in transit is secured with TLS 1.3 across all endpoints. We enforce HSTS (HTTP Strict Transport Security) and use strong cipher suites. API access is exclusively over HTTPS; plain HTTP connections are rejected. Database connection strings, API keys, and secrets are managed through a hardened secrets vault with automatic rotation.
Backup and Disaster Recovery
Your shop data is backed up continuously using write-ahead log (WAL) streaming, enabling point-in-time recovery to any second within the retention window. We take full database snapshots daily, with hourly incremental backups. All backups are encrypted and replicated across multiple geographically separated data centers. Our recovery time objective (RTO) is under 2 hours and our recovery point objective (RPO) is under 5 minutes. Quarterly disaster recovery drills validate these targets.
Role-Based Access Control (RBAC)
FabFlow’s permission system is designed for the realities of a fabrication shop. You can create custom roles with granular permissions — for example, a welder might have read access to work orders and time-clock entry, while a quality inspector can create NCRs (non-conformance reports) and view MTRs (material test reports), and the shop owner has full administrative access. Every permission is audited; all access events are logged and retained for review.
We support multi-factor authentication (MFA) via authenticator apps and hardware security keys (WebAuthn/FIDO2). Single sign-on (SSO) with SAML 2.0 is available on our Enterprise plan, making it easy to integrate with your existing identity provider.
Infrastructure and Monitoring
FabFlow runs on a major cloud provider with data centers that meet ISO 27001, SOC 1/2/3, and FedRAMP standards. We operate in a virtual private cloud (VPC) with network segmentation, strict firewall rules, and intrusion detection. Our platform is continuously monitored for anomalies, and our security team maintains an on-call rotation with a 15-minute acknowledged / 60-minute engaged SLA for critical incidents.
Vulnerability Disclosure
We welcome responsible disclosure of security vulnerabilities. If you believe you’ve found a security issue, please email security@fabflowpro.com. We commit to acknowledging your report within 24 hours and providing a status update within 5 business days. We do not retaliate against researchers who follow our responsible disclosure guidelines.