GridflooSupportTermsPrivacySecurity

Security

Last updated 5 October 2026

Gridfloo holds a company’s work: its cards, flows, files, chat and, when connected, its mail and calendars. This page says plainly how we protect that, what we have tested, and what is not there yet. Questions go to security@gridfloo.com.

Your data stays yours, and separate

You can take everything with you

Signing in

Encryption

Backups, and proof they work

A record of who did what

How we run Gridfloo

Where data is kept

AI

Privacy and GDPR

On request and planned

These are not available yet. If your organisation needs one of them, tell us: it decides what we build next.

WhatStatus
Files in your own storage: your workspace’s files kept in your own S3-compatible bucketOn request
EU data centre: database and files kept in the EUPlanned
Single sign-on (SAML) and user provisioning (SCIM)On request. Domain verification, which it builds on, is in place.
Independent penetration testPlanned
ISO 27001 certificationNot yet. We will say so here when it is under way.

Reporting a vulnerability

If you believe you have found a security problem, write to security@gridfloo.com. We answer quickly, keep you informed while we fix it, and will not take action against good-faith research that avoids other people’s data.