Skip to main content

How secure is Florence? How we protect your data

How Florence keeps the app, the platform and your personal information safe, for healthcare professionals and care organizations.

Written by Stephen Paul

Using Florence means trusting us with important information: identity documents, credentials, bank details and, for care organizations, details about your staff and shifts. We take that seriously. This article explains how we protect your information and what you can do to keep your account safe.

Is Florence certified to a recognized security standard?

Yes. Florence is certified to ISO/IEC 27001, the internationally recognized standard for information security management. An external certification body independently audits our security policies, controls and processes, and we passed our most recent audit in 2026.

If your organization needs a copy of our certificate for procurement or vendor onboarding, just ask your account manager.

Is my data encrypted?

  • Encrypted connections: Every connection to the Florence app and platform uses HTTPS (TLS) encryption, and Florence won't accept an unencrypted connection. This means the information you send, like your login, documents and bank details, can't be read while it's in transit.

  • Private document storage: Documents you upload, like your ID, certificates and credentials, are kept in private, access-controlled cloud storage. They are never publicly available online.

  • Expiring document links: When an authorized person opens a document, Florence creates a secure link to it that expires after a few minutes. A link that gets copied or forwarded stops working shortly afterwards.

How are passwords protected?

  • We never store passwords in plain text. They're protected with one-way hashing (bcrypt), so nobody at Florence can see your password.

  • Florence will never ask for your password by phone, email, text or live chat.

  • If you forget your password, you can reset it yourself with the Forgot password link on the login screen.

  • If you've been inactive for a while, Florence signs you out automatically.

Who can see my information?

Access on Florence depends on your role, so people only see the information their role requires.

  • Healthcare professionals: Care organizations can see the information they need to book you safely, such as your profile, qualifications and compliance documents.

  • Care organizations: Your locations, shifts and staff information are only visible to users on your organization's Florence account.

  • Florence team members: Our team's access is also limited by role, and we monitor how internal accounts are used. If an internal account accesses data at an unusual rate, Florence disables it automatically until our IT team has reviewed it.

Is Canadian data kept separate?

Yes. Florence Canada has its own dedicated instance of the Florence platform with its own database, separate from Florence's services in other countries.

How do you monitor the platform and track changes?

  • Audit trail: Florence records changes to important records, such as profiles, documents, bank details and shifts, including what changed and when.

  • Sensitive data kept out of logs: Details like passwords are automatically removed from our system logs.

  • Continuous monitoring: We monitor the platform around the clock for errors and unusual activity so we can respond quickly.

How do you confirm who I am when I contact support?

Before we discuss or change anything on your account, we confirm that we're speaking to the account holder.

  • The quickest and most secure way to get help is to log in to the Florence app and use live chat. This links the conversation to your account.

  • If you contact us another way, we may ask you some questions to confirm your identity, or ask you to log in to the app first.

  • Bank details can only be updated by you, in the app. For your protection, our team can't change bank details for you.

How can I keep my account safe?

  • Use a strong password that you don't use anywhere else. Aim for at least 12 characters with a mix of letters, numbers and symbols.

  • Consider using a password manager to create and store your passwords.

  • Never share your login details, including with colleagues.

  • Log out when you're finished if you use a shared or public device.

  • Keep your phone and the Florence app up to date.

  • Upload documents and update bank details directly in the app rather than sending them by email.

Watch out for scams. Florence will never ask for your password. If you get a message or call that claims to be from Florence and something feels off, don't click any links or share any details. Contact us directly instead.

What should I do if I think my account has been compromised?

  1. Reset your password right away with the Forgot password link.

  2. Check that your details, especially your email, phone number and bank details, are correct.

  3. Contact us straight away so we can look into it. Use the details below.

My organization has a security questionnaire or specific data requirements. Who do I contact?

We regularly complete security and privacy questionnaires for care organizations. Contact your account manager or email partners.ca@florenceapp.com, and our team will get you what you need, including a copy of our ISO 27001 certificate. Please also contact us if your organization has specific requirements about where data is stored or how long it's kept.

Where can I find out more?

Our Privacy Policy and Terms explain what personal information we collect, why we collect it and your rights.

Did this answer your question?