Security Policy
How we protect your data, and what we commit to doing if something goes wrong.
Draft — pending legal review.This document describes our intended practice but has not completed legal review, and is not yet in force. Please don't rely on it as a binding agreement until it is marked active with an effective date.
How we protect your data
These are the controls in place today, not aspirations.
- Data is encrypted in transit with TLS, and at rest by our infrastructure provider.
- Passwords are stored as one-way hashes. Nobody, including us, can read your password.
- Access to your data is enforced at the database level by row-level security, so an application bug alone cannot expose another customer's records.
- Administrative access to production is limited to those who need it, requires multi-factor authentication, and is logged.
- Backups are encrypted and their restoration is tested.
What we need from you
Account security is shared. Use a strong, unique password, keep your email account secure since it can reset your password, and remove access for people who leave your organisation.
Reporting a vulnerability
Report suspected vulnerabilities to security@founderos.app with enough detail to reproduce the issue. We will acknowledge within two working days and keep you updated.
We will not pursue legal action over good-faith research that respects user privacy, avoids service degradation, and gives us reasonable time to fix the issue before disclosure.
If a breach happens
Stating this in advance is the point: knowing what we will do is worth more than a promise that nothing will go wrong.
- We contain the incident and preserve evidence for investigation.
- We notify affected customers without undue delay, and within 72 hours of confirming a personal-data breach.
- Our notice states what happened, what data was involved, what we have done, and what you should do.
- We notify regulators where legally required.
- We publish a post-incident summary once the investigation concludes.
Planned improvements
Two-factor authentication, session and device management, and exportable audit logs are in development. They are listed here as planned rather than described as available, because overstating security posture is itself a security problem.