Security, Compliance, and Trust at Reflex
We're committed to protecting your data through enterprise-grade security practices and full SOC 2 compliance.
Talk to our team about securityReview the services you will use.
Application hosting, AI-assisted development, and connected services have different data flows. Evaluate the configuration your team intends to run.
Your application
Run on Reflex Cloud or in your own environment. Data access follows the integrations you configure.
Compare deployment optionsAI Builder
Prompts, requirements, and code stay in your project. Hosted and on-premises Builder are separate configurations.
Read about on-premises deploymentServices
The models, databases, and APIs you connect define access, processing locations, and provider terms.
Explore integrationsEnterprise-Grade Security at Every Layer
From data protection to privacy compliance, Reflex is built with security-first principles to meet the needs of modern teams and enterprises.
Data Protection
- Data Encryption
- AES-256 encryption at rest, TLS 1.2+ in transit.
- Database Backups
- Daily encrypted backups with 30-day retention.
- Data Segregation
- Customer data is logically isolated per tenant.
Product Security
- Penetration Testing
- External tests conducted annually.
- Secure Development Lifecycle
- Code reviews, linting, and security scans.
- Dependency Management
- Automated scanning for vulnerabilities.
Enterprise Security
- SSO/SAML
- Supports major identity providers for centralized auth.
- Granular Permissions
- Role-based access control across teams.
- Audit Logs
- Track every access and change in the system.
Data Privacy
- GDPR & CCPA Ready
- Compliant data handling and user rights.
- Data Deletion Requests
- Users can request full data erasure.
- Privacy by Design
- Privacy baked into product architecture.
Bring your requirements. Get the right details.
Discuss the applicable controls, documentation, and terms for your proposed configuration with our team.
Architecture and AI data
Review application data, Builder prompts and code, company context, model providers, processing locations, and retention requirements.
Access and operations
Identify identity providers, user roles, logging needs, infrastructure ownership, and the support responsibilities for your deployment.
Procurement and assurance
Tell us which reports, data-processing terms, and service commitments your review requires so we can discuss the applicable material.