Foxy Audit
← Back to home
Security, availability, and compliance for the reviewer who needs answers in five minutes, not fifty pages.
The short version. Foxy Audit is built so that we structurally cannot see the content we audit. Your prompts and responses are hashed on your infrastructure, before anything reaches us. That is not a policy promise — our database has no column capable of storing raw prompt or response text. Everything below explains how the rest of the platform is secured.
Full detail: Privacy Policy, Section 3 & 5.
Per-organization data isolation is enforced at the database level through PostgreSQL row-level security, using a confined, non-superuser database role for tenant-scoped transactions — not application logic alone. This means a bug in a single API route cannot, by itself, leak one organization's data into another's response.
| Provider | Purpose | Location |
|---|---|---|
| Google LLC / OpenAI, L.L.C. | Interaction grading against your policy — metadata only, never raw content | United States |
| Paddle.com Market Ltd ("Paddle") | Payment processing, invoicing, tax handling; merchant of record for your purchase | Global (UK-headquartered) |
| Payoneer, Inc. | Manual invoicing on select arrangements; how we receive our own revenue from Paddle — never touches customer checkout | United States |
| Google Identity | Optional "Sign in with Google" | United States |
| Brevo SAS | Transactional email | European Union |
| Google Cloud (Ubuntu VM) | Hosting | United States |
We do not currently hold SOC 2, ISO 27001, or a comparable third-party attestation. We consider this normal for our stage and are building toward it deliberately rather than claiming it early — see our roadmap below. If a signed attestation is a hard requirement for your procurement process today, tell us; we're happy to complete a security questionnaire (CAIQ or your own SIG) in the meantime.
Roadmap: ISO 27001 gap analysis — Q2 2027. SOC 2 Type I — intended, but no auditor is engaged yet, so we are not putting a date on it. We would rather tell you that than name a quarter we might miss.
Current architecture runs on a single hosting provider. We target 99.5% monthly uptime at this stage; formal SLA commitments are available as part of an Order Form for paid enterprise plans. See our Service Level Agreement.
If we determine a security incident is reasonably likely to have resulted in unauthorized access to your data, we notify affected workspace administrators without undue delay. Full detail: Privacy Policy, Section 15.
We welcome good-faith security research. See our Responsible Disclosure Policy — good-faith reporters following that process will not face legal action from us.
The foxy-audit SDK is MIT-licensed and published on PyPI. Reviewing its source — including the hashing and PII-detection logic — is the fastest way to independently verify the data-minimization claims on this page, rather than taking our word for them.
Questions this page doesn't answer? Email security@foxyaudit.tech or call +92 3398123944 — we'll answer directly, or point you to the relevant policy section.