Trust & security

Security built in, not bolted on.

Tenants trust your facility with contact, booking, and payment information. StorageFlo.io is designed to keep clear boundaries around that data, especially where third-party systems and payment processors are involved.

SOC 2· roadmapCard data· processor-hostedAudit trails· designed inPrivacy· documented

How we handle your data.

The short version: keep card data with processors, scope account access carefully, and make operational health visible to the teams depending on the booking flow.

Data protection

Sensitive data boundaries are designed into the booking path, especially around payments.

  • Encrypted connections for app and widget traffic
  • Cloud-provider managed encryption for stored application data
  • Card entry and sensitive card handling stay with supported processors

Access control

Account access is scoped around who needs to manage bookings, settings, and launch work.

  • Role-aware admin surfaces for operator teams
  • Session and permission boundaries for account activity
  • Audit history for key admin and booking actions

Infrastructure

The platform relies on established cloud and edge providers rather than custom hosting experiments.

  • Hosted on managed infrastructure and edge delivery services
  • Backup and restore practices are part of launch readiness
  • Edge protection helps shield public booking surfaces

Tenant isolation

Each operator account is treated as its own business context.

  • Account-scoped records for locations, units, bookings, and settings
  • Connector activity tied to the operator account that owns it
  • Exports and audit records organized around the tenant account

Monitoring

Status and support paths are designed to make issues visible quickly.

  • Public status page for the major product surfaces
  • Clear support route for booking, sync, payment, and website issues
  • Incident communication written in operator-readable language

Principles we won't break.

Two lists. What we commit to, and what we will not do. The goal is practical trust for teams putting booking, payment, and tenant workflows online.

We commit to
  • Use encrypted connections for app, admin, and widget traffic
  • Keep sensitive card handling with supported payment processors
  • Make export paths and data ownership clear
  • Prioritize critical security fixes with urgency
  • Keep customer records scoped to the right operator account
  • Preserve audit context for key admin and booking actions
We will never
  • Sell, rent, or lease tenant data to anyone
  • Train third-party AI models on your data
  • Share data across tenants, for any reason
  • Hide basic privacy controls behind an add-on
  • Intentionally store raw payment card numbers on our servers
  • Hide breaches or downplay impact
Security-minded launch

Modern booking with responsible boundaries.

Keep your operating system in place, use supported payment gateways for sensitive card handling, and give tenants a booking path your team can trust.

Processor-hosted cardsAccess-aware setupOperational visibility