Skip to main content
Security is built into every layer of Aflux — from the transport encryption that protects data in motion to the audit logs that record every action taken on your account. Aflux is developed by Atek Software, an EU company, and is designed to meet the compliance requirements of GDPR, eIDAS, and SOC 2 out of the box.

Encryption

All data transmitted between your browser, the Aflux application, and your connected storage providers is protected by TLS (Transport Layer Security) on every plan. There is no unencrypted mode. Documents processed through the E-Signature module are encrypted at rest using 256-bit AES encryption. This applies to documents stored in Aflux Internal Storage as well as temporary document processing during the signing workflow. Documents stored in your own cloud provider (Google Drive, OneDrive, Dropbox) are subject to that provider’s encryption standards, which in all cases meet or exceed industry baselines.

Two-Factor Authentication (2FA)

Two-factor authentication adds a second verification step at login, protecting your account even if your password is compromised. 2FA is available on Pro, Business, and Enterprise plans. To enable 2FA on your account:
  1. Go to Settings → Security → Two-Factor Authentication.
  2. Click Enable 2FA.
  3. Scan the QR code with an authenticator app (such as Google Authenticator, Authy, or 1Password).
  4. Enter the six-digit code from your authenticator app to confirm setup.
  5. Save your backup codes in a secure location.
Account administrators on Business and Enterprise plans can require 2FA for all members of their organization from Settings → Security → Organization Policies.

Audit Logs

Aflux records every significant action performed on your account — logins, document sends, signature completions, QR code scans, settings changes, and more. Audit logs are available under Settings → Audit Log. Audit log retention periods depend on your plan: Each log entry includes the timestamp, the user or system that performed the action, the action type, and the affected resource. Business and Enterprise customers can export audit logs in CSV format for integration with external SIEM tools.

Compliance Certifications

SOC 2 Certified

Aflux holds a SOC 2 Type II certification, independently audited against the Trust Services Criteria for security, availability, and confidentiality.

eIDAS Compatible

E-signatures created through Aflux comply with the EU eIDAS regulation for electronic signatures, making them legally valid across all EU member states.

Security Features by Plan

Single Sign-On (SSO)

Enterprise customers can configure SSO using SAML 2.0 or OIDC-compatible identity providers such as Okta, Azure AD, or Google Workspace. Contact support@aflux.io or your account manager to initiate SSO setup.

Custom Security Policies

Enterprise plans include configurable organization-wide security policies, including:
  • Mandatory 2FA enforcement for all users
  • Session timeout and idle logout rules
  • IP allowlist restrictions
  • Password complexity requirements
These policies are managed by account administrators under Settings → Security → Organization Policies (Enterprise only).

Data Residency

By default, Aflux infrastructure is hosted in the EU. Enterprise customers can request specific data residency configurations to ensure that metadata, audit logs, and any Aflux-processed data remains within a particular geographic region. Contact sales for data residency options.
Data residency applies to data held by Aflux (account metadata, audit logs, analytics). Documents stored in your own cloud provider (Google Drive, OneDrive, Dropbox) are subject to that provider’s data residency policies, not Aflux’s.

Responsible Disclosure

If you discover a security vulnerability in Aflux, please report it responsibly by emailing support@aflux.io with a description of the issue. The Aflux security team will acknowledge your report within 48 hours and work with you on remediation.