Skip to content

Security

What we actually do to protect your data

This page describes controls that are in place today. Where something is planned rather than implemented, it is not on this page.

Controls in place

  • Encryption

    TLS 1.2 or higher in transit with modern cipher suites only. AES-256 at rest. Gateway credentials are sealed with AES-256-GCM and are never readable back through the interface that wrote them.

  • Access control

    Role-based access with a granular permission matrix, enforced server-side on every request. Two-factor authentication is mandatory for all staff accounts.

  • Tenant isolation

    Customer content is partitioned per tenant. On FDE Team, per-engagement boundaries are enforced at retrieval time so one client's code cannot surface in another client's answer.

  • Data residency

    Choose the UK, EU or US at setup. Enterprise deployments run entirely inside infrastructure you control, including fully air-gapped installations.

  • Payment data

    We never see or store card details. Checkout hands off to a regulated payment institution's hosted page, which keeps our PCI DSS scope at SAQ-A.

  • Audit logging

    Privileged actions are written to an append-only log with actor, timestamp and before/after state. Enterprise deployments log every assistant query and citation.

  • Backups

    Encrypted daily database backups with a tested restore procedure. Backup encryption keys are held separately from the backups themselves.

  • No training on your data

    Customer content is never used to train shared models. This is a contractual commitment in our data processing agreement, not a setting.

Reporting a vulnerability

If you believe you have found a security issue, please email billy@falconneststore.com. Include enough detail to reproduce it, and let us know if you intend to publish.

What you can expect from us:

  • Acknowledgement within 24 hours, including at weekends
  • An assessment and remediation plan within five business days
  • Credit in our advisories if you would like it
  • No legal action against good-faith research that stays within the boundaries below

Please do not run automated scanners against production, access or modify data belonging to other customers, or perform denial-of-service testing. If you need a test environment for deeper research, ask us and we will provide one.

Documents available on request

The following are available to customers and prospective customers under NDA where appropriate:

  • Data processing agreement (UK GDPR and EU GDPR)
  • Sub-processor list and locations
  • Security questionnaire responses
  • Penetration test summary
  • Business continuity and incident response summary

Request these from billy@falconneststore.com.