GatesFlow is committed to maintaining the highest standards of data security, privacy, and regulatory compliance to protect your business.
EU General Data Protection Regulation
Full compliance with GDPR requirements for organizations processing EU residents' personal data.
California Consumer Privacy Act
Compliance with CCPA and CPRA requirements for California residents.
Service Organization Control 2 - Type II Audit
Currently undergoing SOC 2 Type II audit, demonstrating our commitment to security, availability, processing integrity, confidentiality, and privacy.
Expected Completion: Q2 2025
SOC 2 Trust Service Criteria:
Information Security Management System
Planning ISO 27001 certification to demonstrate our systematic approach to managing sensitive information and ensuring data security.
Target Date: Q4 2025
GatesFlow is designed to support manufacturers operating under stringent quality management standards:
Automotive Quality Management System standard for automotive production and service parts organizations.
Quality Management System standard applicable to any organization regardless of size or industry.
Quality Management System standard for the aerospace industry, including aviation, space, and defense.
Note: While GatesFlow supports workflows aligned with these standards, your organization is responsible for obtaining and maintaining its own certifications. Our platform provides tools to help you meet documentation and process requirements.
All payment processing is handled by Stripe, a PCI DSS Level 1 certified payment processor. We never store or process credit card information directly on our servers.
Primary Data Center Locations: United States (US-East, US-West)
Backup Locations: Geographically distributed across multiple regions for redundancy
For customers in the European Economic Area (EEA), UK, and Switzerland, we ensure appropriate safeguards for international data transfers:
Enterprise customers can request specific data residency requirements. Contact sales@gatesflow.com for details.
We engage carefully vetted subprocessors to provide our Services. All subprocessors are bound by data protection agreements and security requirements.
| Subprocessor | Service | Location |
|---|---|---|
| Stripe, Inc. | Payment Processing | United States |
| Cloud Infrastructure Provider | Hosting & Infrastructure | United States |
| Email Service Provider | Transactional Emails | United States |
We will notify customers of any changes to our subprocessors at least 30 days in advance.
Enterprise customers may request:
For audit-related requests, contact: legal@gatesflow.com
For questions about our compliance posture, certifications, or to request compliance documentation:
General Compliance: compliance@gatesflow.com
Data Protection Officer: dpo@gatesflow.com
Legal / DPA Requests: legal@gatesflow.com
Security: security@gatesflow.com
This compliance page was last updated on October 28, 2025. We continuously work to enhance our security and compliance posture. Check back regularly for updates on our certification progress.