Privacy and security
Your data is your business. We make it our business to protect it. ThreeFlow is the only Benefits Placement System with HITRUST e1 certification and maintains a SOC 2 Type 2 report, with security, privacy, and compliance built into our platform, our people, and our operations.
Maintaining the highest standards
We hold industry-recognized certifications and undergo independent third-party audits to help you meet your compliance needs.
The only Benefits Placement System with HITRUST e1 certification
Independently examined controls, tested over time
Independently examined controls, tested over time
Trust starts here
Brokers, carriers, and third-party partners trust ThreeFlow to keep their data secure and private, from stable network connectivity to keeping out unauthorized users and safeguarding everything from proposals to renewals.
Security
Privacy
Compliance
Reliability
AI you can trust
AI on ThreeFlow is built for accuracy and accountability.
Tested for accuracy, shared openly
Human review, always
Governed for fairness
Auditable, with proactive notice
Request our security documentation
Running a vendor review? We share our full security package with brokers, carriers, and GAs under NDA: everything your risk, procurement, and compliance teams need in one request.
HITRUST e1 certification letter
SOC 2 Type 2 report
AI governance overview
Contact security@threeflow.com for all security questions and documentation requests.
Frequently asked questions
We want you to understand how your data is collected, protected, and maintained. Here are the questions we hear most from clients and partners.
ThreeFlow protects your data with defense in depth: layered controls across our network, applications, and infrastructure rather than a single perimeter. Access to production systems is tightly restricted, network traffic is isolated within segmented private networks, and our environment is continuously monitored for anomalous activity.
We validate those controls on an ongoing basis: automated vulnerability scanning runs against our systems, and independent third parties perform regular security testing, including penetration testing. If an incident does occur, we follow a documented incident response process to contain and resolve it quickly, and we keep you informed through real-time system status updates.
Your data is encrypted both in transit and at rest. In transit, connections between user devices and ThreeFlow are protected with TLS 1.2 or higher using modern cipher suites. At rest, all data persisted by our applications is encrypted with AES-256.
Encryption keys are centrally managed with strict, access-controlled policies, so the keys that protect your data are themselves protected, rotated, and auditable. Encryption is enforced by default across our systems, not left to individual configuration.
ThreeFlow runs on Amazon Web Services (AWS), architected for high availability across multiple, physically separate availability zones. If any single zone or component fails, your data and the platform stay available. No single point of failure can take the service down or cause data loss.
Your data is backed up automatically on a regular schedule, backups are encrypted, and we periodically test our restore process so recovery works when it's actually needed, not just on paper.
ThreeFlow follows the principle of least privilege: access to customer data is limited to the authorized employees who need it for their role, granted through role-based access controls and reviewed periodically. Every access event is written to an audit trail that we monitor and review.
For your own organization, we provide enterprise administrative controls that put you in charge of who gets in: SAML single sign-on (SSO) to centralize authentication with your identity provider, enforced two-factor authentication (2FA), and SCIM for automated provisioning, so access is granted and, just as importantly, revoked automatically as your team changes.
We ship changes through a controlled software development lifecycle. Every change goes through peer code review and an automated test suite before it can be released, and changes roll out through dedicated staging environments that mirror production so issues are caught before they reach you.
Deployment responsibilities are separated so that no single person can push an unreviewed change straight to production, and releases are monitored so we can identify and roll back problems quickly if anything looks off.
Every ThreeFlow employee completes security and privacy awareness training when they join and on a recurring basis after that, covering phishing, social engineering, secure handling of customer data, and each person's role in protecting it. We also run ongoing awareness activities, such as simulated phishing, to keep security top of mind.
Security is a shared responsibility across technical and non-technical roles alike. It's built into how we hire, onboard, and operate, not treated as a once-a-year checkbox.
ThreeFlow holds its AI to a high bar for testing and accuracy, and we communicate performance proactively to brokers, carriers, and GAs. You always have the option to review AI outputs for accuracy. AI does the heavy lifting, you make the decisions.
We monitor and test for bias, discrimination, accuracy, and drift under senior-management oversight, align our governance with the NIST AI Risk Management Framework, and comply with applicable AI laws and regulations.
We also support contractual audit rights over our AI operations and proactively notify carriers, brokers, and GAs of material risks, performance issues, or regulatory inquiries, so we can meet the bar the most security-conscious partners set.
