Everything a vendor security review asks of PFLB is written down, and most of it is on this page.
Security Officer: Svetlana Matalaeva, security@pflb.us · Trust center: trust.pflb.us · security.txt · Download this page as PDF
Attestations and coverage
If your team has shortlisted PFLB for load testing, the next step belongs to security, legal and procurement. This page is written for them: which documents exist and how to get them, where your data lives, who touches the system, how onboarding runs, and what procurement needs to open a vendor record. Most reviews can start without a signature: six policies are open now, and the SOC 2 report follows the mutual NDA.
Documents and how to get them
Six policies are open to anyone at trust.pflb.us. The rest, including the SOC 2 Type II report, open the day you countersign a mutual NDA there.
| Document | What it shows | Access |
|---|---|---|
| Information Security Policy | How the program is governed | Open |
| Access Control Policy | Who gets access, and how | Open |
| Encryption Policy | Data in transit and at rest | Open |
| Incident Management Policy | What happens when something goes wrong | Open |
| Business Continuity & Disaster Recovery Policy | Resilience posture | Open |
| Data Retention Policy | How long we keep things | Open |
| SOC 2 Type II report | Controls tested over a full year | Under NDA |
| Full policy library (27 further policies and procedures) | Implementation detail | Under NDA |
| Certificate of insurance naming your entity | Cover, with your endorsements | On request |
| Your questionnaire, completed | Your format, returned filled | On request |
| MSA with information security exhibit | The contract terms described on this page | Under NDA |
Request access to the trust center
Leave your work email and we approve access within one business day. In the trust center you countersign one mutual NDA and the restricted documents unlock. After you submit, you can pick a time to talk to our Security Officer.
Where your data lives
Four deployment options. We send you the data-flow diagram for the one you pick.
Who touches the system, and from where
Named engineers, each screened before access is issued, each with a declared work location.
PFLB, Inc. is a US entity. Testing is delivered by contracted engineers rather than employees: the same named people on every engagement. They work from the United States, the United Kingdom and Iceland. Each is screened to the category your policy requires, declares where they work from before access is granted, and is bound by written confidentiality obligations that flow down from your agreement. Every person is sanctions-screened; no one from a sanctioned jurisdiction touches an engagement. If your contract requires all work inside a single jurisdiction with no access from abroad, say so on the first call and we will tell you whether we can staff it that way.
Engineer workstations are company-issued devices under endpoint management: full-disk encryption enforced by policy, anti-malware on every workstation, automatic screen lock after 15 minutes, multi-factor authentication for cloud services and remote access, and VPN for access to the platform. These are controls tested in the SOC 2 Type II report, not a description written for this page.
Subprocessors: Amazon Web Services (platform hosting), Google Workspace (email and documents), Sprinto (compliance monitoring and the trust center). Your agreement obliges us to keep this list current, to give advance notice of changes, and gives you the right to object on reasonable data-protection grounds.
How onboarding runs
- Mutual NDA. One document, usually signed the same day. Everything behind it is already prepared.
- Security package. We release the SOC 2 Type II report in the trust center. Send your questionnaire in whatever format you use; we return it filled.
- Insurance to your schedule. A certificate naming your entity, with the endorsements your contract requires, including waiver of subrogation and additional insured where applicable. We issue certificates ourselves, so turnaround is measured in hours.
- Contract with a security exhibit. Our MSA carries an information security exhibit: breach notice without undue delay and no later than 72 hours, background checks, return or destruction of data within 30 days with written certification, audit rights including an on-site right following a security incident, and a subprocessor list with notice of changes.
- Screening and access. Background checks per person to the category your policy requires, declared work locations, and any security training your side mandates, completed before access is issued.
Procurement and vendor onboarding
Send your questionnaire with the RFP. A questionnaire that arrives after selection lands in the middle of legal review and adds weeks.
Security contact: Svetlana Matalaeva, Security Officer, security@pflb.us. These descriptions are informational; the executed agreement governs.
Reporting a vulnerability
If you believe you have found a security issue in pflb.us, platform.pflb.us or our services, email security@pflb.us with the steps to reproduce it. We acknowledge reports within three business days, keep you informed until the issue is resolved, and do not take legal action against researchers who act in good faith, keep data confidential and avoid service disruption. We do not run a bounty program. The same contact is published at /.well-known/security.txt.