1. Introduction
Security is fundamental to the design, operation and ongoing development of the Flex Platform.
Flex Online (Pty) Ltd ("Flex", "we", "our" or "us") recognises that Customers entrust us with information that is important to their organisations and to the individuals who use the Flex Platform.
We are committed to maintaining appropriate technical, organisational and operational measures designed to protect the confidentiality, integrity and availability of the Flex Platform and the information processed through it.
This Security Overview provides a high-level summary of Flex's approach to security. It should be read together with our:
- Privacy Policy;
- Information Security Policy;
- Responsible AI Policy;
- Platform Terms; and
- Vulnerability Disclosure Policy.
2. Security Principles
Our security programme is built around five core principles:
Confidentiality
Protecting information against unauthorised access or disclosure.
Integrity
Protecting information and platform processes against unauthorised modification, manipulation or destruction.
Availability
Designing the Flex Platform to provide reliable access while maintaining resilience against disruption.
Accountability
Maintaining appropriate governance, auditability and operational oversight.
Continuous Improvement
Regularly reviewing and strengthening security controls as technologies, threats and business requirements evolve.
3. Shared Responsibility
Security is a shared responsibility between Flex, our Customers and Platform Users.
Flex is responsible for:
- operating and maintaining the Flex Platform;
- securing the underlying platform infrastructure;
- protecting Customer environments under our control;
- implementing appropriate security controls;
- monitoring platform health and security;
- responding to security incidents; and
- continually improving our security posture.
Customers are responsible for:
- managing their own organisational security policies;
- assigning appropriate user permissions;
- configuring the Flex Platform appropriately;
- determining who may access Customer Content;
- complying with applicable legislation;
- managing their own endpoint devices and internal networks; and
- educating Platform Users.
Platform Users are responsible for:
- protecting their login credentials;
- following Customer security requirements;
- reporting suspected security incidents;
- using the Flex Platform responsibly; and
- complying with the Platform Terms and Acceptable Use Policy.
4. Identity and Access Management
Access to the Flex Platform is protected through identity and access controls designed to ensure that Platform Users can access only the information and functionality authorised by the relevant Customer.
Security measures may include:
- authenticated user accounts;
- role-based permissions;
- password controls;
- secure session management;
- configurable authentication policies;
- account lifecycle management; and
- access logging.
Customers remain responsible for assigning appropriate permissions to Platform Users.
5. Data Protection
Flex applies reasonable technical and organisational measures designed to protect Customer Content and Personal Information.
Depending on the service and deployment, these measures may include:
- encryption in transit;
- encryption at rest where applicable;
- secure communications;
- access controls;
- logical separation of Customer environments;
- audit logging;
- secure backups;
- secure deletion processes; and
- controlled administrative access.
6. Infrastructure Security
The Flex Platform is hosted on professionally managed cloud infrastructure designed to provide high levels of reliability and security.
Infrastructure security measures may include:
- network segmentation;
- firewall protection;
- infrastructure monitoring;
- operating system hardening;
- vulnerability management;
- patch management;
- malware protection;
- redundancy;
- disaster recovery capabilities; and
- secure administrative access.
Infrastructure technologies evolve over time and may differ between deployments.
7. Application Security
Security forms part of the development and operation of the Flex Platform.
Our approach includes:
- secure software design;
- controlled software deployment;
- defect management;
- vulnerability remediation;
- dependency management;
- change management;
- application logging;
- audit trails; and
- ongoing platform improvements.
Security enhancements are incorporated into the normal lifecycle of the Flex Platform.
8. Monitoring and Incident Response
Flex maintains operational processes designed to:
- monitor platform health;
- identify unusual activity;
- investigate suspected security events;
- contain security incidents;
- restore affected services where necessary;
- communicate with affected Customers where appropriate; and
- improve future resilience through post-incident review.
Security incidents are managed in accordance with applicable legal and contractual obligations.
9. Business Continuity
Flex recognises the importance of service continuity.
Business continuity measures may include:
- secure backups;
- disaster recovery planning;
- infrastructure redundancy;
- recovery procedures;
- operational monitoring; and
- documented response processes.
Recovery objectives may vary depending on the relevant service and contractual commitments.
10. Third-Party Service Providers
Flex works with carefully selected third-party providers where appropriate.
These providers may support services such as:
- cloud infrastructure;
- communications;
- email;
- monitoring;
- analytics;
- integrations;
- payment processing; and
- customer support.
Third-party providers are evaluated as appropriate for the services they provide and are expected to maintain security measures appropriate to the nature of the services performed.
11. Security Awareness
Technology alone does not create security.
Flex promotes security awareness through:
- documented security practices;
- internal operational procedures;
- appropriate staff responsibilities;
- confidentiality obligations;
- continual review of security risks; and
- ongoing improvement of security processes.
12. Responsible Disclosure
Flex encourages responsible reporting of potential security vulnerabilities.
Researchers, Customers and Platform Users who identify a potential security issue are encouraged to report it promptly using the procedures described in the Vulnerability Disclosure Policy.
Flex appreciates responsible disclosure and will investigate reports in accordance with our internal security processes.
13. Compliance
Flex designs and operates the Flex Platform with consideration for applicable legal and regulatory requirements.
Depending on the Customer and deployment, these may include:
- the Protection of Personal Information Act (POPIA);
- the General Data Protection Regulation (GDPR);
- the UK GDPR;
- contractual security obligations; and
- applicable industry requirements.
Compliance responsibilities may differ between Flex, the Customer and Platform Users depending on the particular implementation and processing activities.
14. Continuous Improvement
Security is an ongoing process rather than a fixed outcome.
Flex continually evaluates:
- emerging threats;
- technology developments;
- Customer requirements;
- regulatory changes;
- platform enhancements; and
- operational experience
to strengthen the security of the Flex Platform over time.
15. Related Documents
This Security Overview should be read together with:
- Information Security Policy;
- Privacy Policy;
- Platform Terms;
- Acceptable Use Policy;
- Responsible AI Policy;
- Vulnerability Disclosure Policy; and
- Software Subscription Agreement (where applicable).
16. Contact
Questions relating to security may be directed to:
Flex Online (Pty) Ltd
Email: trust@flexonline.io
Website: www.flexonline.io