A governance company should be the first to say what it has not shipped.
Designing for compliance, not claiming it. If a capability matters to your decision, ask and we will tell you exactly where it stands.
- Signal detection against your thresholds
- Priced routing options with policy checks
- Approval routing and delegated authority
- Append-only, attributed trail with export
- Running above real customer data
- ERP and WMS integration
- Production write-back
- The reversal window
- Cryptographic sealing of the trail
- SOC 2, ISO 27001, GDPR and APPI readiness
Built for regulated industries. Designed for compliance from day one.
Groflex handles operational data from food, healthcare, pharma, and chemical supply chains. Our security posture and compliance roadmap reflect that responsibility.
Current security and compliance status.
This table reflects our current state honestly. We use “designing for” language where a certification is in progress and “compliant” only where it is achieved.
| Item | Status | Detail | Target |
|---|---|---|---|
| Encryption at rest | ACHIEVED | All customer data encrypted at rest in Azure storage | Live |
| Encryption in transit | ACHIEVED | TLS 1.2 minimum for all data in transit | Live |
| Role-based access control | ACHIEVED | Access controlled by role. Customer data accessible only to assigned team member | Live |
| Data residency | ACHIEVED | Azure US and EU regions. Region selection based on customer geography | Live |
| SOC 2 Type II | IN PROGRESS | Audit process initiated. Target completion Q3 2026 | Q3 2026 |
| GDPR | DESIGNING FOR | Architecture and data handling designed for GDPR compliance. Not yet certified. DPA available on request | 2026 |
| EU AI Act Article 12 | DESIGNING FOR | Audit trail architecture designed for Article 12 requirements. Effective August 2026. | August 2026 |
| FSMA 204 | DESIGNING FOR | Lot traceability and decision documentation designed for FSMA 204 requirements | 2026 |
How we handle your data.
Data stays in your region.
Customer data is stored in Azure infrastructure in the region you select. US operators on US infrastructure. EU operators on EU infrastructure. Japan operators on Japan or EU infrastructure depending on deployment type.
No shared model training.
Your operational data is never used to train shared models. Your data improves your deployment only. This is an architectural commitment, not just a policy.
Deletion on request and by policy.
Your source data is deleted the moment your report is delivered, and in no case later than three days from receipt. Confirmed in writing. We hold no copy after deletion. No data is used to train any model. Pilot and enterprise customer data is deleted within 30 days of contract termination, and on request within 72 hours.
DPA available on request.
A standard Data Processing Agreement is available for enterprise customers requiring GDPR or other regulatory compliance documentation. Contact hello@groflex.ai to request one.
Our compliance roadmap.
We are building toward full certification across the regulatory frameworks that matter to our customers. This is the honest timeline.
Q3 2026: SOC 2 Type II completion
August 2026: EU AI Act Article 12 effective date. Our audit trail architecture is designed for compliance.
2026: GDPR formal certification process
2026: FSMA 204 lot traceability validation with food distribution customers
2027: Medical device certification pathway via GoML partnership
Timelines are targets. We update this page when status changes. Last updated June 2026.
Security questions.
For security reviews, vendor questionnaires, or DPA requests, contact hello@groflex.ai. We respond within one business day.
hello@groflex.ai →We show you the number before we sell you anything.
- Backtest01Your data · 1 to 3 days · risk-freeYour last 12 to 24 months replayed. Deleted on delivery, confirmed in writing.
- Pilot02$10,000 · 90 daysOne facility. A written outcome report against your own baseline.
20 minutes. No deck. No sales script.