Security & Compliance
Updated: December 14, 2025
At CitaFlow, the security and protection of our customers' data is our top priority. We implement industry best practices to ensure the confidentiality, integrity, and availability of your information.
Secure Infrastructure
- Encryption in transit: All communications use TLS 1.2+ (HTTPS)
- Encryption at rest: Database encrypted with AES-256
- EU hosting: Data stored in European data centers (GDPR compliant)
- Automatic backups: Daily backups with 30-day retention
Access Control
- Robust authentication: JWT authentication system with short-lived tokens
- CSRF protection: Anti-forgery tokens on all sensitive operations
- Data isolation: Row-Level Security (RLS) for complete tenant separation
- Least privilege principle: Access restricted by user role
Secure Development
- Code review: All code is reviewed before production deployment
- Continuous integration: Automated tests and security analysis on every change
- Dependency management: Automatic vulnerability and OSS license scanning
- Regular updates: Security patches applied as priority
Regulatory Compliance
- GDPR: Full compliance with General Data Protection Regulation
- LOPDGDD: Aligned with Spanish Data Protection Law
- Responsible Open Source: Exclusive use of compatible OSS licenses (MIT, Apache 2.0, BSD)
- Transparency: Clear and accessible privacy policy
Monitoring & Response
- 24/7 monitoring: Automatic alerts for suspicious activity
- Audit logs: Recording of access and critical operations
- Incident response: Documented incident management protocol
- Breach notification: Communication within 72 hours per GDPR
Trusted Providers
We work with industry-leading security providers:
- Supabase: Managed PostgreSQL database with SOC 2 Type II
- Twilio: Communications with ISO 27001 certification
- OpenAI: AI with enterprise privacy policies
- Stripe: Payments with PCI DSS Level 1 certification
Security Contact
If you discover a security vulnerability or have questions about our practices, contact us:
Email: contact [arroba] citaflow [punto] com
We commit to responding to security reports within a maximum of 48 hours.
Our Commitment
Security is not a product, it's an ongoing process. We continuously review and improve our security practices to protect your business data and your customers' data.