Compliance Controls Back to floom.vc ↗

Trust Center

Floom holds the portfolio data of venture and private equity funds. Here is how we protect it.

Compliance

Updated 11 September 2026
SOC 2 Examination
Report issued · as of 9 September 2026 · no exceptions noted
Examination in progress
Type I, Security trust services criteria, examined by an independent licensed CPA firm.

Controls

All 60 controls · no exceptions noted60 controls in scope
Access management9
  • IAM-01User authentication
  • IAM-02Multi-factor authentication
  • IAM-03User access provisioning
  • IAM-04User access deprovisioning
  • IAM-05Periodic user access reviews
  • IAM-06Role-based access & least privilege
  • IAM-07Privileged access management
  • IAM-08Service account & infrastructure credentials
  • IAM-11Third-party app & OAuth integration review
Data protection & assets8
  • DAT-01Encryption at rest & in transit
  • DAT-02Secure data & asset disposal
  • DAT-03Data retention & deletion
  • DAT-04Production data in non-production environments
  • DAT-05Data retention & deletion execution
  • AST-01Information asset inventory
  • AST-02Data classification
  • AST-03SaaS & data asset inventory
AI & model governance4
  • AI-01AI provider inventory & data-use terms
  • AI-02Model provider data-use configuration
  • AI-03Customer data boundaries for AI features
  • AI-04AI interaction logging & retention
Change management5
  • CHG-01Change management process
  • CHG-02Emergency change process
  • CHG-03Environment separation
  • CHG-04Secure development lifecycle
  • CHG-05Security architecture review
Infrastructure & endpoints4
  • NET-02Boundary protection
  • NET-04Production platform hardening
  • END-02Software installation controls
  • END-03Endpoint protection
Monitoring & incident response7
  • VUL-01Vulnerability scanning
  • VUL-04Dependency & platform update management
  • MON-02Security alerting & event triage
  • MON-03Security logging
  • INC-01Incident response plan & training
  • INC-02Incident response execution
  • INC-04Post-incident review & corrective actions
Business continuity2
  • BCP-01BCP/DR plan & testing
  • BCP-03Backup & recovery
Governance, risk & policies10
  • GOV-01Code of conduct & ethics
  • GOV-02Governance oversight
  • GOV-03Organizational structure & responsibilities
  • GOV-04Leadership & advisor oversight of security
  • POL-01Policy suite & governance
  • POL-02Policy communication & accessibility
  • RSK-01Annual risk assessment
  • RSK-02Risk-based control design
  • EVL-01Ongoing control monitoring & evaluation
  • EVL-02Deficiency tracking & remediation
People6
  • PPL-01Background checks
  • PPL-02Job descriptions & competency
  • PPL-03Training & competency development
  • PPL-04Performance & accountability
  • PPL-05Key personnel & continuity
  • PPL-06Contractor & outsourced personnel controls
Vendors & communication5
  • VND-01Vendor risk management
  • VND-02Subservice organization monitoring
  • VND-04Subprocessor change management & notification
  • COM-01Customer commitments & service descriptions
  • COM-02External reporting & inbound communication