1. The short version
Phanz runs on the platform operated by HighLevel Inc., hosted on Google Cloud Platform. That platform undergoes annual SOC 2 Type II assessment, encrypts data at rest with AES-256 and in transit with TLS 1.2+, and maintains EU-U.S. Data Privacy Framework certification.
Security is shared. They secure the platform. We secure how we configure and operate it. You secure your account and your team's access. All three have to hold.
This page describes the controls that protect data in Phanz. It is a description of our posture, not a warranty — see our Terms of Use. HighLevel's own privacy and security page is the authoritative source for the platform layer.
2. Certifications and frameworks
| Framework | Status at the platform layer |
|---|---|
| SOC 2 Type II | Annual assessment against the AICPA criteria for security, availability and confidentiality. |
| EU-U.S. Data Privacy Framework | Certified, with Standard Contractual Clauses as a fallback transfer mechanism. UK and Swiss extensions apply. |
| GDPR / UK GDPR | Tooling for consent management, and access and deletion requests. See our Privacy Policy. |
| CCPA / CPRA | Supported. We do not sell or share personal information for cross-context advertising. |
| CAN-SPAM / TCPA / A2P 10DLC | Opt-out handling and carrier registration are built into the messaging stack. Consent is your responsibility. |
| HIPAA | Supported at the platform layer under a business associate agreement. Not enabled on standard Phanz plans — do not upload PHI unless we have agreed in writing. |
Phanz itself does not hold an independent SOC 2 report. Where a compliance review needs platform-level evidence, request it through us and we will route it to HighLevel's trust centre.
3. Infrastructure
- Hosted on Google Cloud Platform, which carries its own ISO 27001, SOC and physical-security certifications for its data centres.
- Production is network-segmented, with firewalling and DDoS mitigation at the edge.
- Sub-accounts are logically isolated. One customer's data is not visible to another.
- Platform data is stored primarily in US regions. See where your data lives.
4. Encryption
- In transit — TLS 1.2 or 1.3 with 2,048-bit keys on all connections between your browser and the platform. HTTPS is enforced; plain HTTP is redirected.
- At rest — AES-256 for stored platform data.
- Passwords — hashed using industry-standard algorithms and encrypted at rest. Nobody at Phanz or HighLevel can read your password.
- Payment data — card details are tokenised by PCI-compliant processors and never stored on Phanz or platform servers.
5. Access control
Controls available to you
- Two-factor authentication on user accounts. Turn it on for everyone.
- Role-based permissions so team members only see what their job needs.
- Single sign-on where your plan supports it.
- Audit logs recording sign-ins and significant account actions.
Controls on our side
- Access to customer accounts is limited to staff who need it to deliver support, and is granted on a least-privilege basis.
- Administrative access requires multi-factor authentication.
- Access is reviewed periodically and revoked promptly when someone changes role or leaves.
- Staff are bound by confidentiality obligations.
6. Testing and monitoring
- Penetration testing — conducted by independent third parties at the platform layer.
- Vulnerability scanning — continuous scanning of infrastructure and dependencies, with remediation prioritised by severity.
- Logging and alerting — security-relevant events are logged and monitored for anomalies.
- Secure development — code review and dependency management before changes reach production.
7. Vendor management
Every vendor with access to customer data is assessed for security and privacy controls and bound by contract before onboarding. The current list of platform sub-processors is published in HighLevel's sub-processor list and data processing agreement.
If you need a data processing agreement with Phanz directly, email privacy@phanz.vip.
8. Backups and continuity
- Platform data is backed up on an automated schedule, with backups encrypted and stored redundantly.
- Restore procedures are maintained and tested at the platform layer.
- Business continuity and disaster recovery plans are maintained by the platform operator.
Backups are not an export. They protect against platform-level failure, not against you deleting something. Export anything you cannot afford to lose, and export before you cancel.
9. Incident response
A documented incident response process covers detection, containment, eradication, recovery and review. If a security incident affects your personal data, we will notify you without undue delay and, where the GDPR applies, within 72 hours of becoming aware — with what happened, what data was involved, what we have done, and what you should do.
Where the incident originates at the platform layer, our notification follows HighLevel's disclosure to us, and we pass it on promptly.
10. Your part
Most breaches start with a credential, not an exploit. The controls that matter most are the ones you hold:
- Turn on two-factor authentication for every user, without exception.
- Use a unique, strong password and a password manager. Never reuse a password across services.
- Give team members the minimum role they need, and remove access the day someone leaves.
- Review your audit logs periodically for sign-ins you do not recognise.
- Do not upload regulated data — health, payment card, or government identifiers — unless we have agreed in writing that your plan supports it.
- Train your team to recognise phishing. We will never ask for your password.
11. Reporting a vulnerability
If you believe you have found a security vulnerability, email security@phanz.vip with enough detail to reproduce it. We will acknowledge receipt and keep you updated on remediation.
Please give us a reasonable window to fix the issue before disclosing it publicly, and do not access, modify or delete data belonging to anyone else while testing. We will not pursue legal action against researchers who act in good faith within those boundaries.
To report suspected unauthorised access to your own account, email security@phanz.vip immediately and change your password.