---
title: "Security: what we do with your company’s data · Foundiry"
description: "Plain rules, not vague assurances: where your data is hosted, how it is encrypted, who else touches it, what is sent to a model, and how long it is kept."
url: "https://foundiry.com/security"
---

# What we do with your company's data

Financials, contacts and investor conversations deserve plain handling rules, not vague assurances. Here are ours, in the shortest form they fit into.

Your company data is not used to train AI models. AI drafting and reviews run only when you approve them.

## The questions diligence asks

- **Where it runs**: Supabase runs the database, the sign-in system and file storage, in AWS us-east-1 (Northern Virginia, United States). Vercel runs the application and its edge network. Both are US companies. We will confirm this in writing for a diligence questionnaire.
- **Encryption**: HTTPS on every request, with HSTS. The database and file storage are encrypted at rest by the platform. On top of that, any token you give us for another service you have connected is encrypted by us with AES-256-GCM before it is written, so the database never holds a usable copy of it.
- **Keeping companies apart**: Every table has row-level security, so a query for another workspace’s row returns nothing. Separation is enforced by the database, not by the application remembering to filter, and a test walks the live schema and fails the build when a table has no policy.
- **Who else touches it**: Supabase (database, sign-in, files), Vercel (hosting), Stripe (payments), Upstash (the background job queue), Resend (email), Cloudflare (bot checks and mail routing), Sentry (errors), PostHog (product analytics), Gamma (turns a generated deck into slides, only when you ask for one) and Canva (only if you connect your own Canva account). For generated work, Anthropic is the default model provider; a workspace can be pointed at DeepSeek, Groq, OpenAI, Together AI instead. Nothing is sent to a provider you are not using.
- **How long it is kept**: Your data stays while your workspace does. Deleted files are recoverable for 30 days, then scheduled for permanent deletion. You can export everything at any time, and you can ask us to delete the workspace outright.

Found a problem? Write to [security@foundiry.com](mailto:security@foundiry.com). Security reports are read before anything else and acknowledged within two business days. Please do not include a working exploit in the first message. Signed agreements and prior consent versions are issued on request during the beta: [see Legal](https://foundiry.com/legal).

## The rules, in full

## Who can see your data

Between companies Row-level security on every table, enforced by the database

Your identity Every request is checked against your signed-in account

Sensitive changes Important actions can require a fresh one-time code

Support staff Access requires your permission for that support request

## Files & sharing

Storage Files are private and download links expire quickly

Sensitivity Mark files as normal, confidential, restricted, or investor-only

Share links Links can be cancelled immediately

Deletion Deleted files can be recovered for 30 days, then they are removed

## AI handling

What is sent Only the information needed for the action you approved

Before saving Generated output is checked for the expected fields and format

## Your rights

Availability Israel, United States, and European Union. Adults only

Rights Access, correction, export and deletion

Consent We record which terms you accepted and when
