InfoSec Legal Procurement

Security and Procurement

Everything your security, legal and procurement teams are going to ask for. Published before they ask, so the review starts on day one instead of week three.

  • SOC 2 Type II, audited over a full year, plus a third-party pen test
  • Cyber liability carried, not just general liability
  • Cloud, your cloud, or generators inside your perimeter
  • Updated August 21, 2026

Trusted by:

  • Moody's
  • KFC
  • Tinder
  • SOC 2 Type Il SOC 2 Type Il certified
  • Cyber liability Cyber liability insured
  • Zero breaches since 2008 Zero data breaches since 2008

3 Questions Before the Questionnaire

Most of a vendor review is spent discovering which of these three has no answer. Ours are on this page.

  • Yes. The deployment options, the data-handling model and the contract structure are on this page and need no NDA. The SOC 2 Type II report and the penetration test go out the moment a mutual NDA is in place, usually the same day.

  • That is a choice, not a default. We run in our cloud, in yours, or place load generators inside your perimeter so nothing crosses it. We will send a data-flow diagram for whichever one you pick.

  • Named individuals, screened per person, with their locations declared before access is granted. They are the same engineers who run our load testing packages and our performance testing services. If your contract requires everyone to be inside one country, tell us in the first call and we will say plainly whether we can staff it.

How Onboarding Runs

The Order That Keeps It Short

  1. Mutual NDA

    One document, usually signed same day. Everything gated behind it is prepared and waiting rather than assembled on request.

  2. Security package

    SOC 2 Type II report for the period to March 2026 and the most recent third-party penetration test of our platform. Send us your questionnaire and we return it filled rather than asking what format you prefer.

  3. Insurance to your schedule

    Certificate naming your entity, with the endorsements your contract requires. Cyber liability is carried separately from general liability, which is the line most vendors are missing.

  4. Contract with a security addendum

    Our MSA carries an information security exhibit: breach notice within 72 hours, background checks, return or destruction of data within 30 days with written certification, audit rights, a subprocessor list with notice of changes.

  5. Screening and access

    Background checks per person to the category your policy requires, declared work locations, and any security training your side mandates, completed before access is issued.

Where Your Data Lives

  • Our cloud

    Fastest to start. Load generated from our infrastructure, results in our platform, your data never leaves the test environment you point us at.

  • Your cloud

    Generators run in your AWS or Azure account. Compute is yours, the control plane is ours, and nothing about the run leaves your boundary.

  • Inside your perimeter

    On-premise generators for systems that cannot be reached from the internet at all. Common in banking, utilities and anything behind a hard network edge.

  • Masked, not copied

    Where lower environments need production-shaped data, we generate anonymised sets that preserve shape and referential integrity without carrying the real values.

Don't Take Our Word
For It. Take Theirs.

Rating: 5 out of 5 stars

I was highly satisfied working with PFLB. They’re a fantastic one-stop shop for software performance, with everything you need—their platform and skilled engineers. I’ve used them four times to load test the College Board software before big updates, and it all went smoothly. Plus, I love that they store all the testing data, so we can track performance capacity over time.

Bob Burke

Bob Burke

President, Folderwave

4 engagements, 4 successful launches — zero SAT-day outages

Rating: 5 out of 5 stars

It was a pleasure working with PFLB, and I’d recommend them for performance testing. They quickly got up to speed with our complex software architecture and were super productive in setting up our load test environment in the cloud. They were really dedicated to improving our product with their strong expertise in performance optimization.

Steve Opel

Steve Opel

Principal Technology Manager, NOV CTES

Critical bug found 48 hours pre-launch - $2M revenue protected

Get a Free Consultation

or scroll down to book a specific time slot

Pick a Time. Talk to an Engineer

30-minute call with the people who would actually run the tests and sign the addendum.

What happens on this call:

You describe your review process and your constraints. We tell you what we can produce immediately, what needs an NDA, and where we would fail your requirements.

  • Mutual NDA signed before the call if you prefer
  • Security package prepared in advance, not promised
  • We name our gaps rather than waiting for you to find them
  • Trusted by 300+ companies
5.0 Clutch SOC 2 Cyber insured

A Vendor Review Is Not the Risk. Starting It Late Is.

Most of the delay in a security review is waiting for documents that could have been ready. Ours are.

Security Questions We Get Asked

Do you have SOC 2?

Yes. A SOC 2 Type II report for the observation period 3 March 2025 to 25 March 2026, covering Security, Availability and Confidentiality, issued by an independent service auditor. Available under a mutual NDA, and we send it together with the third-party penetration test rather than one at a time.

Do you have ISO 27001?

No, and it is a deliberate choice rather than a gap we are working through. The two are not the same kind of evidence. ISO 27001 certifies that a management system exists and is designed correctly. A SOC 2 Type II report is an independent auditor testing whether the controls actually operated, on real samples, across a stated period of time. If what you need to know is whether the controls worked rather than whether they were written down, Type II is the stronger artifact, and it is the one we invest in.

If your policy names ISO 27001 specifically and cannot accept an equivalent attestation, raise it in the first conversation rather than at contract stage, and we will tell you plainly that we do not have it.

Will you complete our security questionnaire?

Yes, and we would rather receive it early. Send it with the RFP instead of after selection: it is the single step that most often adds weeks, because it usually arrives once legal review has already started.

What insurance do you carry?

Commercial general liability, employer's liability, excess, professional liability and cyber liability, placed with Chubb and The Hartford. We issue a certificate naming your entity with the endorsements your contract requires, including waiver of subrogation and additional insured where applicable. Cyber cover is carried separately, which is the line vendors most often turn out to be missing.

Where are your engineers located?

We are a US entity and the delivery team includes US-based W-2 engineers. We do not claim that every engineer in the company is US-based, because that would not be true. If your contract requires all work inside one jurisdiction with no access from abroad, say so at the first call and we will tell you honestly whether we can staff it that way.

Do you run background checks?

Yes, per person, to the category your policy requires, and we declare which countries each person has previously worked in when your screening has to cover them. If someone declines screening, they do not join the engagement.

What happens to our data when the engagement ends?

Return or destruction within 30 days, with written certification on request. It is a clause in the agreement rather than a promise in an email.

How quickly do you notify us of a security incident?

Without undue delay and no later than 72 hours, written into the contract.

Can you test without production data?

Usually yes. Where a realistic test genuinely needs production-shaped data, we generate an anonymised set that preserves the shape and referential integrity of the original without carrying real values.

Who else touches our systems?

We maintain a current subprocessor list, give advance notice before it changes, and your agreement carries the right to object on data-protection grounds. Audit rights include an on-site right following any security incident.