Security

Your customer book is the business — we treat it like one.

Foreman handles contact details, conversation history, and revenue data for small businesses. Here's how we keep it safe.

In short

Encrypted everywhere, hosted on AWS, no model training on customer data — and you can delete everything in one click.

SOC 2 Type II · in progress
Encryption in transit & at rest
99.9% uptime SLA on Fleet
You stay in control of every send
How we protect it

Six controls, plain.

01

Encryption everywhere

TLS 1.3 in transit. AES-256 at rest. Per-tenant encryption keys for sensitive fields.

02

Cloud-native infrastructure

Hosted on AWS in US-East. Network isolation, private subnets, least-privilege IAM.

03

SSO & access control

Google SSO supported. Role-based access for team accounts. Session expiry, audit logs.

04

Your data is yours

Export your full data anytime, in CSV or JSON. Delete on request — full purge within 30 days.

05

Backups & recovery

Continuous backup. Point-in-time restore. Tested DR every quarter.

06

Privacy by default

We don't train AI models on your data. We don't sell or share it. You stay the data controller.

Vulnerability disclosure

If you've found something, write to security@foreman.work. Reasonable bug bounties paid for valid reports. We respond within one business day.

Subprocessors

We use AWS (hosting), Anthropic (LLM), Twilio (SMS), Google (OAuth & email), and Stripe (billing). Full list and DPAs available on request.

Compliance

SOC 2 Type II audit in progress, expected Q3 2026. CCPA & GDPR-ready data deletion endpoints. HIPAA is out of scope — Foreman is not designed for protected health information.