HITRUST e1 | SOC 2 Type 2

Privacy and security

Your data is your business. We make it our business to protect it. ThreeFlow is the only Benefits Placement System with HITRUST e1 certification and maintains a SOC 2 Type 2 report, with security, privacy, and compliance built into our platform, our people, and our operations.

Maintaining the highest standards

We hold industry-recognized certifications and undergo independent third-party audits to help you meet your compliance needs.

The only Benefits Placement System with HITRUST e1 certification

Validated annually by a HITRUST-authorized external assessor, not a self-attestation
44 foundational security controls covering essential cyber hygiene
Mapped to HIPAA, NIST, ISO 27001, and dozens of other authoritative frameworks

Independently examined controls, tested over time

Conducted by an independent, licensed CPA firm
Tests control effectiveness across a multi-month review period, not a single date
Covers the Security, Availability, & Confidentiality Trust Services Criteria
Full report available under NDA through our security documentation portal

The only Benefits Placement System with HITRUST e1 certification

Validated annually by a HITRUST-authorized external assessor, not a self-attestation
44 foundational security controls covering essential cyber hygiene
Mapped to HIPAA, NIST, ISO 27001, and dozens of other authoritative frameworks

Independently examined controls, tested over time

Conducted by an independent, licensed CPA firm
Tests control effectiveness across a multi-month review period, not a single date
Covers the Security, Availability, & Confidentiality Trust Services Criteria
Full report available under NDA through our security documentation portal

Trust starts here

Brokers, carriers, and third-party partners trust ThreeFlow to keep their data secure and private, from stable network connectivity to keeping out unauthorized users and safeguarding everything from proposals to renewals.

Security

We build security into our platform, people, and operations to protect systems and information.

Privacy

We take active precautions against the unauthorized disclosure of personal and confidential information.

Compliance

We certify our products and undergo independent third-party audits.

Reliability

We keep information and systems available for our customers while blocking unauthorized access.
Responsible AI

AI you can trust

AI on ThreeFlow is built for accuracy and accountability.

Tested for accuracy, shared openly

We hold our AI to a high accuracy bar and share performance openly.

Human review, always

You can always review outputs. AI does the heavy lifting, you make the decisions.

Governed for fairness

We monitor for bias and drift under senior oversight, aligned to the NIST AI framework.

Auditable, with proactive notice

We support contractual audit rights and flag material risks proactively.

Request our security documentation

Running a vendor review? We share our full security package with brokers, carriers, and GAs under NDA: everything your risk, procurement, and compliance teams need in one request.

Note: Shared under NDA. Most requests are turned around within 2 business days.

HITRUST e1 certification letter

Independent proof of our current, annually validated HITRUST e1 certification and its scope.

SOC 2 Type 2 report

The full examination of our security, availability, and confidentiality controls over the review period.

AI governance overview

How we handle your data with AI: testing and accuracy, fairness monitoring, governance, and audit rights.

Contact security@threeflow.com for all security questions and documentation requests.

Frequently asked questions

We want you to understand how your data is collected, protected, and maintained. Here are the questions we hear most from clients and partners.

How does ThreeFlow keep my data secure?

ThreeFlow protects your data with defense in depth: layered controls across our network, applications, and infrastructure rather than a single perimeter. Access to production systems is tightly restricted, network traffic is isolated within segmented private networks, and our environment is continuously monitored for anomalous activity.

We validate those controls on an ongoing basis: automated vulnerability scanning runs against our systems, and independent third parties perform regular security testing, including penetration testing. If an incident does occur, we follow a documented incident response process to contain and resolve it quickly, and we keep you informed through real-time system status updates.

How does ThreeFlow encrypt my data?

Your data is encrypted both in transit and at rest. In transit, connections between user devices and ThreeFlow are protected with TLS 1.2 or higher using modern cipher suites. At rest, all data persisted by our applications is encrypted with AES-256.

Encryption keys are centrally managed with strict, access-controlled policies, so the keys that protect your data are themselves protected, rotated, and auditable. Encryption is enforced by default across our systems, not left to individual configuration.

How does ThreeFlow protect against data loss?

ThreeFlow runs on Amazon Web Services (AWS), architected for high availability across multiple, physically separate availability zones. If any single zone or component fails, your data and the platform stay available. No single point of failure can take the service down or cause data loss.

Your data is backed up automatically on a regular schedule, backups are encrypted, and we periodically test our restore process so recovery works when it's actually needed, not just on paper.

How does ThreeFlow prevent unauthorized access?

ThreeFlow follows the principle of least privilege: access to customer data is limited to the authorized employees who need it for their role, granted through role-based access controls and reviewed periodically. Every access event is written to an audit trail that we monitor and review.

For your own organization, we provide enterprise administrative controls that put you in charge of who gets in: SAML single sign-on (SSO) to centralize authentication with your identity provider, enforced two-factor authentication (2FA), and SCIM for automated provisioning, so access is granted and, just as importantly, revoked automatically as your team changes.

How does ThreeFlow ensure the platform functions correctly?

We ship changes through a controlled software development lifecycle. Every change goes through peer code review and an automated test suite before it can be released, and changes roll out through dedicated staging environments that mirror production so issues are caught before they reach you.

Deployment responsibilities are separated so that no single person can push an unreviewed change straight to production, and releases are monitored so we can identify and roll back problems quickly if anything looks off.

Do ThreeFlow employees undergo security training?

Every ThreeFlow employee completes security and privacy awareness training when they join and on a recurring basis after that, covering phishing, social engineering, secure handling of customer data, and each person's role in protecting it. We also run ongoing awareness activities, such as simulated phishing, to keep security top of mind.

Security is a shared responsibility across technical and non-technical roles alike. It's built into how we hire, onboard, and operate, not treated as a once-a-year checkbox.

How does ThreeFlow use AI with my data?

ThreeFlow holds its AI to a high bar for testing and accuracy, and we communicate performance proactively to brokers, carriers, and GAs. You always have the option to review AI outputs for accuracy. AI does the heavy lifting, you make the decisions.

We monitor and test for bias, discrimination, accuracy, and drift under senior-management oversight, align our governance with the NIST AI Risk Management Framework, and comply with applicable AI laws and regulations.

We also support contractual audit rights over our AI operations and proactively notify carriers, brokers, and GAs of material risks, performance issues, or regulatory inquiries, so we can meet the bar the most security-conscious partners set.