Trust

Files you upload are evidence, and we treat them that way

This page is maintained by FlagFake to answer common security and privacy questions. It describes our intended practices and is not an independent certification or audit result.

FlagFake security shield representing encryption, access controls and audit protections

Platform controls

Transport

Encryption in transit

All traffic to and from the platform is served over HTTPS.

Storage

Encryption at rest

Uploaded files and generated reports are stored encrypted.

Access

Least privilege

Role-based permissions restrict who can view a file, its findings and its report.

Audit

Activity logging

Access, escalation and deletion events are recorded against each case.

Intake

Upload validation

Files are type-checked, size-limited and scanned before analysis begins.

Abuse

Rate limiting & CAPTCHA

Automated abuse protections apply to public upload and authentication endpoints.

Shared responsibility

FlagFake operates the platform controls above. Your organisation remains responsible for who you grant access to, what you upload, the lawful basis for verifying a third party's documents, and the retention window you configure.

Our commitment

Data use

Files are used to perform the verification you requested. We do not sell customer data, and we do not train models on customer uploads without explicit consent.

Your control

Retention & deletion

Choose a retention period per document type, or delete any file and its derived artefacts on demand.

Security questionnaires, penetration test summaries and compliance documentation are provided under NDA. Report a vulnerability to security@flagfake.com.