Last Updated: January 15, 2025
Hosted on Azure
Enterprise-grade cloud infrastructure
Encrypted at rest & in transit
AES-256 & TLS 1.2+ encryption
99.9% uptime target
Reliable service availability
At FlexOps, LLC ("FlexOps", "we", "us", or "our"), security is a top priority. We are committed to protecting your data and maintaining the highest standards of security across our platform and services.
This Security page outlines our security practices, measures, and commitments to keeping your information safe and secure.
TLS Everywhere: All connections to our services use TLS (Transport Layer Security) 1.2 or higher with no exceptions. We enforce HTTPS for all web traffic and secure connections for all API communications.
All data transmitted between your device and our servers is encrypted using industry-standard TLS (Transport Layer Security) 1.2 or higher. This ensures that your data cannot be intercepted or read by unauthorized parties during transmission.
TLS Everywhere (No Exceptions): We enforce TLS encryption for all connections with no exceptions. All web traffic uses HTTPS, and all API communications require secure TLS connections. We do not support unencrypted connections.
All sensitive data stored in our databases is encrypted at rest using AES-256 encryption. This includes customer information, shipping data, and other confidential data.
Encryption keys are managed using secure key management systems and are never stored alongside the encrypted data. Access to encryption keys is strictly controlled and monitored.
We implement strong authentication mechanisms including:
Access to customer data is restricted based on the principle of least privilege. Employees and contractors only have access to the minimum data and systems necessary to perform their job functions.
All access to systems and data is logged and monitored. We regularly review access logs to detect and respond to any unauthorized access attempts.
Our services are hosted on Microsoft Azure, providing enterprise-grade cloud infrastructure with redundant systems, automated backups, and global availability. We leverage Azure's security features, compliance certifications, and built-in security controls.
Azure Compliance Certifications: Azure maintains numerous compliance certifications that benefit our services, including:
Data Residency: Customer data is stored in Azure data centers located in the United States. We can accommodate data residency requirements for international customers upon request. All data transfers comply with applicable data protection laws, including GDPR Standard Contractual Clauses (SCCs) for international transfers.
Azure Security Services: We utilize Azure's comprehensive security services including:
Uptime Target: We maintain a 99.9% uptime target for our core services. Our infrastructure is designed with redundancy and failover capabilities to minimize downtime and ensure service availability.
Our network infrastructure is protected by Azure firewalls, intrusion detection systems, and DDoS mitigation services. We regularly update and patch our systems to address security vulnerabilities.
All systems are hardened according to security best practices, including:
We follow secure software development practices including:
Our APIs are secured using authentication tokens, rate limiting, and request validation. API keys are managed securely and can be revoked at any time.
We carefully vet and monitor third-party services and integrations. All third-party providers must meet our security standards and are subject to regular security assessments.
FlexOps maintains approved API integrations with major shipping carriers. All carrier integrations are authorized, comply with carrier terms of service, and meet carrier security requirements.
Merchant API Integration
UPS API Integration
FedEx API Integration
DHL Express API Integration
Carrier Compliance: All carrier API integrations are maintained in compliance with each carrier's terms of service, security requirements, and API usage guidelines. We regularly review and update our integrations to ensure ongoing compliance.
We maintain regular automated backups of all critical data. Backups are encrypted and stored in geographically distributed locations to ensure data availability and recovery.
Restore Testing: We regularly test our backup and restore procedures to ensure data can be recovered quickly and accurately in the event of data loss or system failure. Our restore testing includes both automated and manual verification processes.
We retain data only for as long as necessary to provide our services and comply with legal obligations. Data is securely deleted when it is no longer needed.
Customer data is logically and physically isolated to prevent unauthorized access. Each customer's data is segregated to ensure privacy and security.
We continuously monitor our systems for security threats, anomalies, and potential breaches. Our security operations team is available 24/7 to respond to security incidents.
We maintain a comprehensive incident response plan that outlines procedures for detecting, responding to, and recovering from security incidents. This plan is regularly tested and updated.
Incident Response Email: For security incidents, please contact us immediately at security@flexops.io. We respond to security incidents promptly and prioritize critical issues.
In the event of a data breach that affects your personal information, we will notify affected users and relevant authorities in accordance with applicable laws and regulations.
We maintain a public status page where you can check the real-time status of our services, view uptime history, and receive updates about any incidents or maintenance.
Status Page: Visit our API Status page to view the current status of all FlexOps services, including API endpoints, integrations, and infrastructure components.
We are committed to maintaining compliance with relevant security standards and regulations, including:
We regularly undergo security assessments and audits to ensure ongoing compliance and identify areas for improvement.
Payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. We do not store or process credit card information directly. All payment data is encrypted and handled securely by Stripe.
For more information about Stripe's security practices, please visit Stripe's Security page.
We recommend that users take the following steps to enhance their account security:
We regularly update our security practices and may modify this Security page to reflect changes in our security measures, technologies, or legal requirements. We will notify users of any material changes to our security practices.
If you discover a security vulnerability or have concerns about our security practices, please report it to us immediately. We take security issues seriously and will investigate and address them promptly.
Security Contact: security@flexops.io
Support: support@flexops.io
Please include as much detail as possible about the security issue, including steps to reproduce if applicable.
If you have questions about our security practices or this Security page, please contact us at: