FLO · Trust Center

Flo Ev Trust Center

Trust center

FLO maintains a public trust center documenting SOC 2 Type 2, SOC 2 Type 1, and PCI DSS compliance.

EnergyCanadaEV ChargingElectricityGridDemand ResponseInteroperabilityOCPPOCPIOpenADRCharge Point OperatorQuebec
Trust center: https://trust.flo.com/

Certifications & Compliance

SOC 2 Type 2SOC 2 Type 1PCI DSS

Source

Trust Center

flo-ev-trust-center.yml Raw ↑
generated: '2026-07-27'
method: searched
probe: true
url: https://trust.flo.com/
title: FLO Trust Center
platform: Vanta
platform_evidence: >-
  trust.flo.com is a CNAME to 67eec921f6325d6c3432909a.cname.vantatrust.com; the
  page is served from assets.vanta.com with canonical https://trust.flo.com and
  <title>FLO Trust Center</title>. HTTP 200, TLS 1.3, HSTS max-age=31536000;
  includeSubDomains.
content_access: >-
  The trust center renders client-side from a signed Vanta GraphQL API
  (POST /graphql returns "Missing `signature` or `signedAt`"), so the
  certification and subprocessor lists are not readable anonymously via HTTP.
  The certification below is therefore evidenced from FLO's own press release
  rather than scraped from the trust center shell.
certifications:
- name: SOC 2 Type 2
  auditor: BARR Advisory
  announced: '2024-10-22'
  source: https://www.flo.com/news/flo-achieves-major-cybersecurity-soc-2-type-2-certification/
  quote: >-
    FLO states the SOC 2 Type 2 audit "covers a wide range of security controls
    and supports operational effectiveness over time", was performed by "BARR
    Advisory, a leading provider of cloud-based security and compliance
    solutions", and that FLO will recertify annually.
- name: SOC 2 Type 1
  auditor: BARR Advisory
  announced: '2024'
  status: superseded by SOC 2 Type 2
  source: https://www.flo.com/en-ca/press-release/flo-affirms-commitment-to-network-and-data-security-with-soc-2-type-1-certification/
- name: PCI DSS
  status: claimed-in-marketing
  note: >-
    FLO states its network-connected stations include a PCI-DSS compliant
    payment system. This is a product statement on FLO's own pages, not an
    attestation document, and no AOC or certificate number is published.
not_found:
  iso_27001: not published
  fedramp: not applicable / not published
  hipaa: not applicable
  csa_star: not published
  subprocessor_list: not readable anonymously
evidence:
- {source: 'https://trust.flo.com/', status: 200, kind: trust center, keywords: [trust center, security, compliance]}
- {source: 'https://www.flo.com/news/flo-achieves-major-cybersecurity-soc-2-type-2-certification/', kind: press release, certification: SOC 2 Type 2}