What we do with your company's data
Financials, contacts and investor conversations deserve plain handling rules, not vague assurances. Here are ours, in the shortest form they fit into.
Your company data is not used to train AI models. AI drafting and reviews run only when you approve them.
The questions diligence asks
- Where it runs
- Supabase runs the database, the sign-in system and file storage, in AWS us-east-1 (Northern Virginia, United States). Vercel runs the application and its edge network. Both are US companies. We will confirm this in writing for a diligence questionnaire.
- Encryption
- HTTPS on every request, with HSTS. The database and file storage are encrypted at rest by the platform. On top of that, any token you give us for another service you have connected is encrypted by us with AES-256-GCM before it is written, so the database never holds a usable copy of it.
- Keeping companies apart
- Every table has row-level security, so a query for another workspace’s row returns nothing. Separation is enforced by the database, not by the application remembering to filter, and a test walks the live schema and fails the build when a table has no policy.
- Who else touches it
- Supabase (database, sign-in, files), Vercel (hosting), Stripe (payments), Upstash (the background job queue), Resend (email), Cloudflare (bot checks and mail routing), Sentry (errors), PostHog (product analytics), Gamma (turns a generated deck into slides, only when you ask for one) and Canva (only if you connect your own Canva account). For generated work, Anthropic is the default model provider; a workspace can be pointed at DeepSeek, Groq, OpenAI, Together AI instead. Nothing is sent to a provider you are not using.
- How long it is kept
- Your data stays while your workspace does. Deleted files are recoverable for 30 days, then scheduled for permanent deletion. You can export everything at any time, and you can ask us to delete the workspace outright.
Found a problem? Write to security@foundiry.com. Security reports are read before anything else and acknowledged within two business days. Please do not include a working exploit in the first message. Signed agreements and prior consent versions are issued on request during the beta: see Legal.