Filro

Security and delivery

Procurement teams need to know exactly what a vendor touches. This page states the system boundary, the data involved, how access is granted and revoked, and which controls Filro does not currently provide.

System boundary

Filro works only inside the systems named in the written statement of work.

  • Conversion surfaces in scope (website, landing pages, forms and booking paths)
  • The CRM instance and the pipeline objects named in the statement of work
  • Lead routing, follow-up sequencing and notification paths
  • Automation and integration connections between the named systems
  • Analytics, tracking and attribution properties for the systems in scope
  • Domain, DNS, hosting and SSL records required for the implementation

Data categories

  • Business contact data submitted through forms and booking paths
  • Contact and quote submissions sent through the website
  • Aggregated analytics and event data
  • Configuration metadata for the systems in scope
  • Filro does not request or process payment card numbers; card data stays with the payment processor

Access model

  • Least-privilege access granted by the client, per system
  • Named individual accounts — no shared logins
  • Two-factor authentication required wherever the platform supports it
  • Access is time-boxed to the engagement and revoked at handoff
  • Client accounts remain in the client's name and ownership at all times

Credential handling

  • Credentials are transferred through the client's password manager or an equivalent secure channel
  • Secrets are stored in a secrets manager, never in code, tickets or email
  • Credentials are rotated or revoked at the client's request and at handoff

Subprocessors

Filro uses a limited set of infrastructure providers. The current list is provided in writing during procurement and updated on request.

  • Application hosting and edge delivery
  • Managed database and authentication
  • Transactional email delivery
  • Payment processing
  • Any additional platform the client explicitly asks Filro to operate within

Delivery controls

  • Changes are staged and reviewed before production
  • Each module is tested against written acceptance criteria
  • Written status records for every project stage
  • Runbooks, architecture documentation and recorded training at handoff
  • Rollback path documented before production launch

Incidents

  • Suspected incidents affecting client data are reported in writing without undue delay
  • Reports include what is known, what is unknown and the remediation in progress
  • Post-incident summaries are written, not verbal

Not currently offered

Filro states these plainly instead of implying capability during procurement.

  • SOC 2, ISO 27001 or comparable certification
  • Independent penetration testing
  • HIPAA, PCI-DSS or similar compliance attestations
  • 24/7 human support or a contractual uptime SLA
  • Custom security questionnaires answered with claims Filro cannot evidence

Security questions during procurement

Written security questions are answered in writing before any agreement is signed. Send them to filro.site@gmail.com or include them with your Revenue Audit request.

Request a Revenue Audit