Enterprise Security Standards

Built With Enterprise-Grade Security Practices

Your customer feedback and business data are protected with strict multi-layer defense.

TLS 1.3 & AES-256 Encryption

Data is encrypted in transit and at rest using bank-grade cryptographic protocols.

OAuth 2.0 Google Integration

We never store raw password credentials. Access is securely delegated via Google OAuth.

Role-Based Access Controls (RBAC)

Enforce strict team roles (Admin, Manager, Viewer) across multi-location accounts.

GDPR & Privacy Ready

Built with privacy-first architecture, explicit consent flows, and right-to-be-forgotten data mechanisms.

How We Protect Your Data

A detailed look at the controls behind the summary above, plus an honest account of where we are on formal compliance — we'd rather tell you exactly what's true today than overstate it.

Encryption in transit and at rest

All traffic to and from flyclicks.io is encrypted with TLS. OAuth tokens and other secrets are encrypted at rest using AES-256-GCM before they touch our database.

OAuth 2.0 for Google sign-in

We connect to your Google Business Profile through Google's official OAuth 2.0 flow. We never see or store your Google password, and you can revoke access at any time from your Google Account or your flyclicks.io dashboard.

Role-based access control

Team members are scoped to Admin, Manager, or Viewer roles, so people only see and do what their role allows across your locations.

Full audit trail

Sensitive actions — connecting a profile, changing automation rules, publishing a reply, inviting a user — are recorded in an audit log tied to the account that took them.

Per-organization data isolation

Every organization's data is logically isolated, so one customer's business and review data is never exposed to another.

Enterprise SSO (OIDC)

Enterprise customers can require single sign-on through any OpenID Connect provider — Okta, Microsoft Entra ID, and others. We do not currently support SAML.

Our Compliance Status, Honestly

flyclicks.io is a pre-launch product. We have designed the platform with security best practices from day one — including the encryption, access control, and audit logging described above — but we have not yet completed a formal third-party audit or certification such as SOC 2, ISO 27001, or PCI-DSS, and we do not claim to hold one. We are not a HIPAA-certified Business Associate; our architecture follows HIPAA-conscious data-handling practices, which is a different and lower bar than a completed compliance audit. Payment card data is handled entirely by our PCI-compliant payment processors (Stripe and Razorpay) — we never see or store full card numbers. We plan to pursue formal certifications as the business scales, and will update this page the moment any of them are actually completed.

Reporting a Security Issue

If you believe you've found a security vulnerability in flyclicks.io, please email support@flyclicks.io with details. We investigate every report and will follow up directly.

For how we collect and use data, see our Privacy Policy and Data Processing Addendum.