Floom
Trust Center
Compliance
Controls
Contact security
Compliance
Controls
Back to floom.vc ↗
Trust
Center
Floom holds the portfolio data of venture and private equity funds. Here is how we protect it.
Floom AI, Inc.
security@floom.vc
Privacy Policy
Report a vulnerability
Compliance
Updated 11 September 2026
SOC 2 Examination
Report issued · as of 9 September 2026 · no exceptions noted
Examination in progress
Type I, Security trust services criteria, examined by an independent licensed CPA firm.
Controls
All 60 controls · no exceptions noted
60 controls in scope
Expand all
Access management
9
IAM-01
User authentication
IAM-02
Multi-factor authentication
IAM-03
User access provisioning
IAM-04
User access deprovisioning
IAM-05
Periodic user access reviews
IAM-06
Role-based access & least privilege
IAM-07
Privileged access management
IAM-08
Service account & infrastructure credentials
IAM-11
Third-party app & OAuth integration review
Data protection & assets
8
DAT-01
Encryption at rest & in transit
DAT-02
Secure data & asset disposal
DAT-03
Data retention & deletion
DAT-04
Production data in non-production environments
DAT-05
Data retention & deletion execution
AST-01
Information asset inventory
AST-02
Data classification
AST-03
SaaS & data asset inventory
AI & model governance
4
AI-01
AI provider inventory & data-use terms
AI-02
Model provider data-use configuration
AI-03
Customer data boundaries for AI features
AI-04
AI interaction logging & retention
Change management
5
CHG-01
Change management process
CHG-02
Emergency change process
CHG-03
Environment separation
CHG-04
Secure development lifecycle
CHG-05
Security architecture review
Infrastructure & endpoints
4
NET-02
Boundary protection
NET-04
Production platform hardening
END-02
Software installation controls
END-03
Endpoint protection
Monitoring & incident response
7
VUL-01
Vulnerability scanning
VUL-04
Dependency & platform update management
MON-02
Security alerting & event triage
MON-03
Security logging
INC-01
Incident response plan & training
INC-02
Incident response execution
INC-04
Post-incident review & corrective actions
Business continuity
2
BCP-01
BCP/DR plan & testing
BCP-03
Backup & recovery
Governance, risk & policies
10
GOV-01
Code of conduct & ethics
GOV-02
Governance oversight
GOV-03
Organizational structure & responsibilities
GOV-04
Leadership & advisor oversight of security
POL-01
Policy suite & governance
POL-02
Policy communication & accessibility
RSK-01
Annual risk assessment
RSK-02
Risk-based control design
EVL-01
Ongoing control monitoring & evaluation
EVL-02
Deficiency tracking & remediation
People
6
PPL-01
Background checks
PPL-02
Job descriptions & competency
PPL-03
Training & competency development
PPL-04
Performance & accountability
PPL-05
Key personnel & continuity
PPL-06
Contractor & outsourced personnel controls
Vendors & communication
5
VND-01
Vendor risk management
VND-02
Subservice organization monitoring
VND-04
Subprocessor change management & notification
COM-01
Customer commitments & service descriptions
COM-02
External reporting & inbound communication