Legal

Security at Foyla.

Last updated: September 2026

This page describes how we protect client data and the systems we build. Procurement and security teams can request our current security documentation, questionnaire answers, and subprocessor list at [email protected].

How we think about it

The systems we build run inside our clients' environments and act on real data. We design them the way a security team would want a new internal system designed: least privilege, a complete audit trail, human review on anything new, and a fast path to stop or roll back. We apply the same standard to our own access while we build.

Where the software runs

Data protection

Access during the build

The delivered system

Vulnerability management

Business continuity

Security roadmap

We are an early-stage company and say so plainly. The following controls are on our near-term roadmap rather than already certified. We will update this page as they ship.

If any of these are a gating requirement for you, let us know. We can often commit to a timeline in the Software Development Agreement.

Compliance

US state privacy laws (CCPA/CPRA, Colorado, Connecticut, Virginia, Utah) and GDPR/UK GDPR are addressed in our Privacy Policy and DPA. SOC 2 and ISO are on the roadmap above.

Contact

Security questions and vulnerability reports: [email protected]