`n

Fivo Security & Privacy FAQ

SOC 2 Type II compliant. GDPR ready. HIPAA compatible. On-premise available. Your data is never used for training. Here is every security detail.

Compliance & Certifications

StandardStatusDetails
SOC 2 Type IICompliantAnnual third-party audit
GDPRCompliantDPA available, EU processing option
HIPAACompatibleBAA available, on-premise option
Encryption (transit)TLS 1.3All connections
Encryption (rest)AES-256BYOK for Enterprise
On-PremiseAvailableEnterprise plan, air-gapped
Zero Data RetentionAvailableNothing written to disk
FedRAMPRoadmap 2027On-premise alternative

All 20 Security Questions

Yes. SOC 2 Type II compliant with annual third-party audits. Reports available under NDA.
HIPAA compatible with BAA available. On-premise deployment for complete data sovereignty. Zero data retention mode ensures PHI is never written to disk.
Absolutely not. Your data is never used for training AI models. Contractually guaranteed. Your data is your data.
Yes. Enterprise plans include on-premise deployment. Run in your VPC, private cloud, or air-gapped environment. Nothing leaves your infrastructure.
AES-256 encryption at rest, TLS 1.3 in transit. Never logged, never displayed in full. Envelope encryption with customer-specific keys. Rotation supported.
AWS US-East-1 (Virginia) and EU-West-1 (Ireland). Enterprise customers choose their region or deploy on-premise. All data centers SOC 2 certified.
Yes. SAML 2.0 and OpenID Connect on Pro and Enterprise. Works with Okta, Azure AD, Google Workspace, OneLogin.