Trust
Files you upload are evidence, and we treat them that way
This page is maintained by FlagFake to answer common security and privacy questions. It describes our intended practices and is not an independent certification or audit result.

Platform controls
Transport
Encryption in transit
All traffic to and from the platform is served over HTTPS.
Storage
Encryption at rest
Uploaded files and generated reports are stored encrypted.
Access
Least privilege
Role-based permissions restrict who can view a file, its findings and its report.
Audit
Activity logging
Access, escalation and deletion events are recorded against each case.
Intake
Upload validation
Files are type-checked, size-limited and scanned before analysis begins.
Abuse
Rate limiting & CAPTCHA
Automated abuse protections apply to public upload and authentication endpoints.
Shared responsibility
FlagFake operates the platform controls above. Your organisation remains responsible for who you grant access to, what you upload, the lawful basis for verifying a third party's documents, and the retention window you configure.
Our commitment
Data use
Files are used to perform the verification you requested. We do not sell customer data, and we do not train models on customer uploads without explicit consent.
Your control
Retention & deletion
Choose a retention period per document type, or delete any file and its derived artefacts on demand.
Security questionnaires, penetration test summaries and compliance documentation are provided under NDA. Report a vulnerability to security@flagfake.com.