TrustFlare
ProductDemoPricingRURequest a pilot
All documentsTerms of useAcceptable useRussian personal-data policyPrivacy policy (GDPR/CCPA)Data processing agreementSubprocessorsCookie policySecurityISO 27001 and infrastructureCompliance statements

Legal and compliance

ISO 27001 and infrastructure

Updated: 21 July 2026

TrustFlare has no formal ISO certification. We use a certified infrastructure provider and document our own self-assessment.

Infrastructure provider: Cloudflare

The public website uses Cloudflare Pages; the demo is behind Cloudflare Tunnel and the access gate. Lead-form data use a managed Cloudflare database.

Cloudflare holds independently assessed certifications covering the infrastructure we use:

  • ISO/IEC 27001: information security management.
  • ISO/IEC 27701 and 27018: privacy and cloud personal-data protection.
  • SOC 2 Type II.
  • PCI DSS.

Cloudflare publishes current certificates and their scope in its Trust Center.

TrustFlare’s ISO 27001 position

TrustFlare follows Annex A control objectives. Our internal compliance procedures and self-assessment indicate that applicable controls are implemented. Measures are described in Security.

TrustFlare is not formally ISO 27001 certified. Meeting control objectives is not a certificate. Descriptions of measures and self-assessment results are available for due diligence on request.

Control mapping: ISO, 152-FZ and GDPR

The same measures address Russian and European requirements:

  • Information-security policies (A.5): 152-FZ Article 18.1, internal policies and responsible person; GDPR Article 24, accountability.
  • Access management (A.8/A.9): 152-FZ Article 19; GDPR Article 32.
  • Cryptography (A.8.24): 152-FZ Article 19; GDPR Article 32, encryption.
  • Secure development (A.8.25–8.28): 152-FZ Article 19; GDPR Article 25, privacy by design.
  • Incident management (A.5.24–5.28): 152-FZ Roskomnadzor notification within 24/72 hours; GDPR Articles 33–34, 72 hours.
  • Suppliers (A.5.19–5.22): delegated processing under 152-FZ; GDPR Article 28, DPA and Subprocessors.

Compliance enquiries

Contact [email protected] for security questionnaires, due diligence and available supporting documents.

© 2026 TrustFlare
BlogLegalPrivacySecurity
Get startedEarly-stage product