Foxy Audit ← Back to home

Foxy Audit Trust Center

Security, availability, and compliance for the reviewer who needs answers in five minutes, not fifty pages.

Last updated: 4 August 2026 · Version 1.7

The short version. Foxy Audit is built so that we structurally cannot see the content we audit. Your prompts and responses are hashed on your infrastructure, before anything reaches us. That is not a policy promise — our database has no column capable of storing raw prompt or response text. Everything below explains how the rest of the platform is secured.

Document details

Contents

  1. Data we never receive
  2. Encryption
  3. Tenant isolation
  4. Audit integrity
  5. Access control
  6. Sub-processors
  7. Certifications status today
  8. Availability
  9. Incident notification
  10. Responsible disclosure
  11. Open source

1. Data we never receive

Full detail: Privacy Policy, Section 3 & 5.

2. Encryption

3. Tenant isolation

Per-organization data isolation is enforced at the database level through PostgreSQL row-level security, using a confined, non-superuser database role for tenant-scoped transactions — not application logic alone. This means a bug in a single API route cannot, by itself, leak one organization's data into another's response.

4. Audit integrity

5. Access control

6. Sub-processors

ProviderPurposeLocation
Google LLC / OpenAI, L.L.C.Interaction grading against your policy — metadata only, never raw contentUnited States
Paddle.com Market Ltd ("Paddle")Payment processing, invoicing, tax handling; merchant of record for your purchaseGlobal (UK-headquartered)
Payoneer, Inc.Manual invoicing on select arrangements; how we receive our own revenue from Paddle — never touches customer checkoutUnited States
Google IdentityOptional "Sign in with Google"United States
Brevo SASTransactional emailEuropean Union
Google Cloud (Ubuntu VM)HostingUnited States

7. Certifications status today

We do not currently hold SOC 2, ISO 27001, or a comparable third-party attestation. We consider this normal for our stage and are building toward it deliberately rather than claiming it early — see our roadmap below. If a signed attestation is a hard requirement for your procurement process today, tell us; we're happy to complete a security questionnaire (CAIQ or your own SIG) in the meantime.

Roadmap: ISO 27001 gap analysis — Q2 2027. SOC 2 Type I — intended, but no auditor is engaged yet, so we are not putting a date on it. We would rather tell you that than name a quarter we might miss.

8. Availability

Current architecture runs on a single hosting provider. We target 99.5% monthly uptime at this stage; formal SLA commitments are available as part of an Order Form for paid enterprise plans. See our Service Level Agreement.

9. Incident notification

If we determine a security incident is reasonably likely to have resulted in unauthorized access to your data, we notify affected workspace administrators without undue delay. Full detail: Privacy Policy, Section 15.

10. Responsible disclosure

We welcome good-faith security research. See our Responsible Disclosure Policy — good-faith reporters following that process will not face legal action from us.

11. Open source

The foxy-audit SDK is MIT-licensed and published on PyPI. Reviewing its source — including the hashing and PII-detection logic — is the fastest way to independently verify the data-minimization claims on this page, rather than taking our word for them.

Questions this page doesn't answer? Email security@foxyaudit.tech or call +92 3398123944 — we'll answer directly, or point you to the relevant policy section.

Home · Terms · Privacy · Cookies · Report Abuse · All legal documents
© 2026 Foxy Audit. Cryptographic compliance, not a promise.