Support & Help
Getting Fantastical and Cardhop approved by your IT or security team
Your organization may require a security review before apps can be used with a Google Workspace or Microsoft 365 account. Here are some resources to help your organization perform a security review.
Start at the Trust Center
Our Trust Center has most of what your IT or security team needs. It includes:
- Our SOC 2 Type II report: We are SOC 2 Type II compliant, which means our security controls have been audited by an independent third party.
- Annual penetration test summary: We perform a third-party penetration test and security audit every year.
- Microsoft 365 Certification: Fantastical has completed Microsoft 365 Certification.
- A list of live security controls.
Data privacy
If your organization has questions about what data leaves your devices, take a look at our Privacy FAQ.
Our apps are designed to keep your data private by keeping as much of it on your device as possible.
For EU-based organizations
EU-based organizations can opt in to our Data Processing Agreement at flexibits.com/dpa.
If your admin needs to allow the app
If you hit an error connecting your work account, your admin will need to add us to the allowed list of apps. These pages have the client IDs and a full breakdown of every OAuth scope we request and why:
A template you can send
Feel free to copy and adapt:
I'd like to use Fantastical for my work calendar. The vendor publishes a trust center at https://flexibits.com/security with their SOC 2 Type II report, annual penetration test summary, infrastructure diagram, and subprocessor list.
A few details that may be relevant: calendar and contact data, including account credentials, stays on the device rather than on vendor servers. Their servers are on Google Cloud Platform in the US. Their privacy details are at https://flexibits.com/privacy/faq and their EU DPA is at https://flexibits.com/dpa.
If you need to allow the app in Google Workspace, the client IDs and requested scopes are documented at https://flexibits.com/support/kb/186.
If you need to allow the app in Microsoft 365, the client IDs and requested scopes are documented at https://flexibits.com/support/kb/189.
Flexibits is able to answer security or privacy questions directly as well.
Still have questions?
If your security team has a questionnaire to fill out or a question we haven't answered, contact us and we're happy to work with them directly.