Third Party Index

Snapshot 22098

Document
Security page
URL
https://flaree.app/security
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
244505 bytes
SHA-256 (raw)
39a3041ea0058cf1be4c7e3eece25f8a78d78986d6985f00e6615bc9aa6a008d
SHA-256 (normalized text)
ff03f43db8ea63e81781ec2a442de353611f2d3c78fe6a6f3605dfb0b6b7e5c3

Normalized text

Scripts and page chrome removed; this is what change detection compares.

Security
Flaree is built and run in the European Union. This page states where your data sits, how it is protected, who can reach it, and who to contact about it.
EU data residency
Flaree runs on Amazon Web Services in the eu-central-1 region, Frankfurt, Germany. Application servers, the production database and its backups are all in that region. Your data does not leave the EU.
EU legal entity
Flaree is operated by Mobile Reality sp. z o.o., registered in Warsaw, Poland. The GDPR is domestic law for us, and your data stays inside the EU, so there is no third-country transfer to cover: no Data Privacy Framework, no Standard Contractual Clauses, no transfer impact assessment.
Encryption
Data at rest is encrypted with AES-256. Data in transit is encrypted with TLS 1.2 or higher — the load balancer and the CDN both reject earlier versions.
Access control
Each account carries a role, and each role carries an explicit set of permissions. A user reaches only their own company's data, and only the parts their role allows. Company administrators assign and revoke roles from the dashboard.
Backups
The production database is backed up daily, in the same region. Backups are retained for 30 days and then deleted.
Sub-processors
We name every third party that processes data on our behalf, and what each one handles.
See the sub-processors list
Retention, deletion and export
Your data is kept while your account is open. Administrators export their employee data from the dashboard at any time, and can request a full machine-readable export by email. When you ask us to delete an account, we remove it from the production database, and the last backup copy expires 30 days later.
Reporting a vulnerability
Report a vulnerability to [email protected]. Include the steps to reproduce it and the account or URL affected. The same contact details are published in machine-readable form.
[email protected]