All policies

Security Policy

How we protect your data, and what we commit to doing if something goes wrong.

Draft — pending legal reviewVersion 0.1.0Updated 8 August 2026

Draft — pending legal review.This document describes our intended practice but has not completed legal review, and is not yet in force. Please don't rely on it as a binding agreement until it is marked active with an effective date.

How we protect your data

These are the controls in place today, not aspirations.

  • Data is encrypted in transit with TLS, and at rest by our infrastructure provider.
  • Passwords are stored as one-way hashes. Nobody, including us, can read your password.
  • Access to your data is enforced at the database level by row-level security, so an application bug alone cannot expose another customer's records.
  • Administrative access to production is limited to those who need it, requires multi-factor authentication, and is logged.
  • Backups are encrypted and their restoration is tested.

What we need from you

Account security is shared. Use a strong, unique password, keep your email account secure since it can reset your password, and remove access for people who leave your organisation.

Reporting a vulnerability

Report suspected vulnerabilities to security@founderos.app with enough detail to reproduce the issue. We will acknowledge within two working days and keep you updated.

We will not pursue legal action over good-faith research that respects user privacy, avoids service degradation, and gives us reasonable time to fix the issue before disclosure.

If a breach happens

Stating this in advance is the point: knowing what we will do is worth more than a promise that nothing will go wrong.

  • We contain the incident and preserve evidence for investigation.
  • We notify affected customers without undue delay, and within 72 hours of confirming a personal-data breach.
  • Our notice states what happened, what data was involved, what we have done, and what you should do.
  • We notify regulators where legally required.
  • We publish a post-incident summary once the investigation concludes.

Planned improvements

Two-factor authentication, session and device management, and exportable audit logs are in development. They are listed here as planned rather than described as available, because overstating security posture is itself a security problem.