Fivo Security & Privacy FAQ
SOC 2 Type II compliant. GDPR ready. HIPAA compatible. On-premise available. Your data is never used for training. Here is every security detail.
Compliance & Certifications
| Standard | Status | Details |
|---|---|---|
| SOC 2 Type II | Compliant | Annual third-party audit |
| GDPR | Compliant | DPA available, EU processing option |
| HIPAA | Compatible | BAA available, on-premise option |
| Encryption (transit) | TLS 1.3 | All connections |
| Encryption (rest) | AES-256 | BYOK for Enterprise |
| On-Premise | Available | Enterprise plan, air-gapped |
| Zero Data Retention | Available | Nothing written to disk |
| FedRAMP | Roadmap 2027 | On-premise alternative |
All 20 Security Questions
Yes. SOC 2 Type II compliant with annual third-party audits. Reports available under NDA.
HIPAA compatible with BAA available. On-premise deployment for complete data sovereignty. Zero data retention mode ensures PHI is never written to disk.
Absolutely not. Your data is never used for training AI models. Contractually guaranteed. Your data is your data.
Yes. Enterprise plans include on-premise deployment. Run in your VPC, private cloud, or air-gapped environment. Nothing leaves your infrastructure.
AES-256 encryption at rest, TLS 1.3 in transit. Never logged, never displayed in full. Envelope encryption with customer-specific keys. Rotation supported.
AWS US-East-1 (Virginia) and EU-West-1 (Ireland). Enterprise customers choose their region or deploy on-premise. All data centers SOC 2 certified.
Yes. SAML 2.0 and OpenID Connect on Pro and Enterprise. Works with Okta, Azure AD, Google Workspace, OneLogin.