This page explains our security practices, how we handle customer content, and the controls available to your team.
For information about the personal data we collect and how we use it, see our Privacy Policy.
General practices
- All staff use two-factor authentication.
- Access to administrative tools is restricted to authorized staff, with permissions configured per account.
- Employees and contractors agree to confidentiality obligations as part of their work agreements.
- Access to company systems is revoked when staff leave.
Authentication and access control
Speakflow supports email and password authentication and sign-in through supported identity providers. Passwords are hashed using bcrypt.
Teams and workspaces let customers organize access to shared work. Speakflow checks permissions for viewing and managing scripts within accounts.
Public sharing links allow recipients to access shared content without a Speakflow account. Share these links only with your intended audience.
Encryption
Communication between your browser and Speakflow is encrypted using HTTPS. Customer data stored in our databases is encrypted at rest, and database connections require encryption.
Hosting
Speakflow is hosted on Heroku, which runs on Amazon Web Services (AWS) infrastructure. Our application databases are hosted in the United States. Cloudflare is also part of our infrastructure.
Heroku and AWS maintain independently audited compliance programs, including ISO 27001 certification and SOC 2 reports. More information is available from Heroku and AWS.
Customer content
Scripts are stored in Speakflow so you can access them across devices and collaborate with your team. Saved recordings are uploaded for storage and playback.
Voice tracking uses speech recognition, which may process microphone audio through external speech services. Microphone access requires browser or operating-system permission.
Additional details about specialized processing services are available under NDA for customer security reviews.
Logging, retention, and backups
We use PostHog for product analytics. Application logs are retained in Axiom for 30 days.
Our databases use Heroku Continuous Protection, which continuously backs up database changes and supports point-in-time recovery over the previous four days.
Customers can delete scripts and recordings and request account deletion. Deletion is processed asynchronously. Backup copies and other retained records are subject to separate retention periods.
To request deletion of your analytics data, email team@speakflow.com.
Payment processing
Payments are processed through Stripe. Card details are collected through Stripe’s checkout rather than stored on Speakflow’s servers. Speakflow stores billing references and subscription information to manage your account.
Software development and vulnerability detection
All code changes require human approval and are tested through quality assurance (QA) and continuous integration (CI) before production deployment.
We run automated security checks as part of development and use automated tools to keep dependencies up to date. Security vulnerabilities are prioritized and patched promptly, with urgent issues taking precedence over routine work.
Frequently asked questions
Is Speakflow SOC 2 audited or ISO 27001 certified?
Speakflow does not currently hold a SOC 2 report or ISO 27001 certification, but we’d like to pursue them in the future. Heroku and AWS, which provide the infrastructure hosting our application and databases, maintain their own independently audited security certifications and reports.
How do I report a security concern?
Email team@speakflow.com to report a potential vulnerability or security concern.
Can you provide more information for our security review?
Yes. Additional security and infrastructure details are available under NDA. Contact team@speakflow.com to discuss your requirements.