Folvern

Folvern Trust Center

See the trust boundaries before you depend on Folvern.

We show what is verified today, what still needs work, and which Founder Beta limits remain in place. Folvern does not claim certifications or maturity that have not been independently established.

Current controls visible No false certifications Beta limitations disclosed

The same operating model also governs trust.

Current posture, risk, ownership, next action, and evidence stay visible so customers can review the boundaries before relying on the platform.

01 Security signalAuth and tenant boundary

Supabase Auth and organization membership determine access.

02 Risk classifiedBeta limitation

Provider, legal, recovery, and support boundaries are named before a customer depends on them.

03 Owner decisionScope access carefully

Beta customers should avoid regulated sensitive data until compliance review is complete.

04 Next actionOperate the release gates

Continue backup and restore drills, external monitoring review, attorney review, and production incident practice before broader availability.

05 EvidenceKeep verification traceable

Migration records, isolation results, CI, health checks, rollback materials, and approvals support each release decision.

What is in place, what is still being finished.

We use plain status labels so the current trust posture is easy to review.

Current
Security overviewAuthentication, application controls, headers, rate limiting, tenant testing

Node server, Supabase Auth, organization-scoped access, security headers, rate limiting, and dedicated tenant-isolation verification are present for the current migration set.

Current
Privacy and data handlingBeta restrictions remain explicit

Privacy documents and legal acceptance are present. Users are instructed not to store regulated sensitive data during Founder Beta.

Current
Authentication and rolesRole-aware organization access

Authenticated sessions and Workspace Owner, Workspace Admin, Team Member, and Business Client roles are enforced through backend authorization and row-level security.

Current
Multi-tenant isolationOrganization and client boundaries verified

Organization and client relationships are server-scoped and protected by RLS, with dedicated cross-owner and client-portal isolation checks.

Current
Backup and recovery evidenceDatabase restore proof available

Fresh production database backup verification and a separate-target restore drill are complete. Storage recovery evidence covers the present placeholder-only bucket state.

In progress
Availability, email delivery, and incident practiceNo public SLA is claimed

Health and monitoring endpoints exist and operating procedures are documented. An open launch gate remains: production email delivery must be qualified before broader launch; continued drills, alert routing, recovery-email qualification, and customer-notification terms remain launch work.

Current
Responsible disclosure pathFounder-supervised review

A public Security Contact route exists without exposing a personal address. Formal disclosure and testing-authorization terms remain subject to attorney review.

Planned
Compliance roadmapNo unsupported certification claims

Folvern does not claim SOC 2, ISO 27001, HIPAA, GDPR certification, or equivalent third-party certification. Broader launch requires further legal, privacy, and security review.

Beta limitations are part of the trust posture.

Folvern is not yet positioned as a regulated-data system or enterprise-certified platform. The beta is appropriate for founder-supervised evaluation, not unattended high-risk production use.

Acceptable for beta Small founder-supervised teams Manual onboarding and support Non-regulated operational data
Needs review first Regulated or highly sensitive data should wait for customer compliance review.
Before scale Final legal review Production email delivery Monitoring and incident drills

Trust Center FAQs.

Honest answers for prospects reviewing Folvern before account creation.

Does Folvern have SOC 2, ISO 27001, HIPAA, or GDPR certification?

No. Folvern does not currently claim SOC 2, ISO 27001, HIPAA, GDPR certification, or any equivalent third-party certification. Compliance review is part of the roadmap before broader public launch.

Can I store regulated sensitive data during beta?

No, not unless your organization has completed its own compliance review and explicitly accepts the risk. Founder-supervised beta is intended for operational workflow validation.

How is customer workspace data separated?

Folvern uses organization membership, authenticated sessions, role-aware behavior, and Supabase row-level security to scope records by tenant.

What happens if there is an incident?

During beta, incidents are handled through founder-supervised support and documented response procedures. Formal public incident communication and SLA commitments are planned later.

Are backups automatic?

A fresh production database backup has been verified and restored successfully to a separate target. Folvern still does not promise a recovery time or unsupported automatic-backup behavior.

Review trust before you request access.

If your team is comfortable with the current beta boundaries, request access and test Folvern with one real operating signal.