Skip to content

Compliance

Afi follows major industry regulations and undergoes independent audits as part of its SOC 2 compliance program. Contact Afi's Data Protection Officer at privacy@afi.ai if you need more information or have questions about a country- or industry-specific regulation that is not covered here.

SOC 2 Type II certification

Service Organization Control (SOC) 2 is a framework that requires service providers such as Afi to establish and follow strict information security policies and procedures. These controls cover the security, availability, processing integrity, and confidentiality of customer data.

Afi is SOC 2 Type II compliant, and our auditor is IS Partners, LLC.

SOC 2 provides detailed information and assurance about the security, availability, and processing integrity of a service provider's systems. Unlike SOC 1, it does not focus on controls related to customers' financial reporting. A Type II report evaluates how controls operated over a period of time, while a Type I report evaluates controls at a specified point in time.

To request Afi's SOC 2 Type II report, complete the Mutual Non-Disclosure Agreement and contact Afi Sales at sales@afi.ai.

Afi also publishes a SOC 3 report, which describes its Trust Services Criteria controls and is available without an NDA.

Download the SOC 3 report

Cloud Security Alliance

The Cloud Security Alliance (CSA) operates the Security, Trust, Assurance, and Risk (STAR) Registry, a cloud security provider assurance program that documents the security and privacy controls of cloud services.

Afi follows the CSA STAR principles and is included in the CSA STAR Registry.

GDPR

The General Data Protection Regulation (GDPR) regulates data protection in the European Union (EU) and the European Economic Area (EEA). Afi complies with GDPR. Afi capabilities and practices that address major GDPR requirements include:

  • Data location: Customers can select a predefined destination to store and process their backup data within the EU.
  • Right to erasure: Afi removes data from its systems in a timely manner upon request. Customers can delete selected backups or submit data deletion requests to permanently remove individual backed-up files or email messages.
  • Security: Customer data is encrypted both in transit and at rest. Afi follows a secure software development lifecycle and is independently audited as part of its SOC 2 Type II certification.
  • Records of processing activities: The Afi audit log records actions performed in the platform and allows customers to retrieve these records when required.
  • Data Protection Officer: Contact Afi's Data Protection Officer at privacy@afi.ai.

Data Privacy Framework program

The Data Privacy Framework (DPF) Program, developed by the United States and the European Commission, succeeds the Privacy Shield Program. It provides a mechanism for transferring personal data from the EU to the United States in a manner consistent with EU data protection law.

Afi Technologies Inc participates in the EU-U.S. Data Privacy Framework, its UK Extension, and the Swiss-U.S. Data Privacy Framework for non-HR personal data. See Afi's official U.S. Department of Commerce participant profile for certification details.

Afi's Data Processing Addendum includes the Standard Contractual Clauses (SCCs) validated by the Court of Justice of the European Union as a mechanism for international transfers of personal data. Afi will enter into the Data Processing Addendum when its services are used to back up personal data belonging to EU residents.

We will enter into the DPA if you use Afi to back up personal data of EU residents. To do it, please download and sign the DPA, then send it to Afi Sales (sales@afi.ai) for processing.

HIPAA

Afi complies with HIPAA regulations. For customers that process Protected Health Information (PHI) and Personally Identifiable Information (PII), Afi will enter into a Business Associate Agreement.

If you need to enter into the HIPAA BAA with Afi, please sign our standard BAA form and send it to Afi Sales (sales@afi.ai).

Student data privacy

Afi limits access to student education records and handles information according to institutional direction in accordance with FERPA. When Afi is used in a school setting, the school manages personal information from children under 13 in compliance with COPPA, and Afi acts only as the school's authorized agent.

UK regulations

NHS Data Security and Protection Toolkit

The NHS Data Security and Protection Toolkit (DSPT) helps organizations evaluate their compliance with ten data security standards established by the National Data Guardian. Afi is certified with the NHS DSPT. See Afi's NHS DSPT certification.

Cyber Essentials

Cyber Essentials is a UK government-backed certification scheme developed in 2014 following consultation with the Information Security Forum (ISF), the British Standards Institution (BSI), IASME, businesses, and professional bodies. The scheme is currently overseen by the National Cyber Security Centre (NCSC) and delivered by IASME.

Afi earned Cyber Essentials certification through a self-assessment of its systems that was independently verified. Current certificates can be found using the official IASME Cyber Essentials certificate search.

NCSC Cloud Security Principles

The NCSC Cloud Security Guidelines help organizations evaluate the security of cloud services before adoption. Afi services meet the framework's 14 Cloud Security Principles, and compliance with these principles is independently tested during Afi's annual SOC 2 audit.

Canadian regulations

The Personal Information Protection and Electronic Documents Act (PIPEDA) governs how organizations handle personal information and gives individuals the right to access and request corrections to personal information collected about them. Afi complies with PIPEDA requirements and uses appropriate safeguards to protect personal information.

The Personal Health Information Protection Act (PHIPA) establishes principles for the collection, use, and disclosure of personal health information (PHI). Afi complies with PHIPA and uses appropriate security and privacy practices to protect PHI.