Supabase Auth and organization membership determine access.
Folvern Trust Center
See the trust boundaries before you depend on Folvern.
We show what is verified today, what still needs work, and which Founder Beta limits remain in place. Folvern does not claim certifications or maturity that have not been independently established.
The same operating model also governs trust.
Current posture, risk, ownership, next action, and evidence stay visible so customers can review the boundaries before relying on the platform.
Provider, legal, recovery, and support boundaries are named before a customer depends on them.
Beta customers should avoid regulated sensitive data until compliance review is complete.
Continue backup and restore drills, external monitoring review, attorney review, and production incident practice before broader availability.
Migration records, isolation results, CI, health checks, rollback materials, and approvals support each release decision.
What is in place, what is still being finished.
We use plain status labels so the current trust posture is easy to review.
Node server, Supabase Auth, organization-scoped access, security headers, rate limiting, and dedicated tenant-isolation verification are present for the current migration set.
Privacy documents and legal acceptance are present. Users are instructed not to store regulated sensitive data during Founder Beta.
Authenticated sessions and Workspace Owner, Workspace Admin, Team Member, and Business Client roles are enforced through backend authorization and row-level security.
Organization and client relationships are server-scoped and protected by RLS, with dedicated cross-owner and client-portal isolation checks.
Fresh production database backup verification and a separate-target restore drill are complete. Storage recovery evidence covers the present placeholder-only bucket state.
Health and monitoring endpoints exist and operating procedures are documented. An open launch gate remains: production email delivery must be qualified before broader launch; continued drills, alert routing, recovery-email qualification, and customer-notification terms remain launch work.
A public Security Contact route exists without exposing a personal address. Formal disclosure and testing-authorization terms remain subject to attorney review.
Folvern does not claim SOC 2, ISO 27001, HIPAA, GDPR certification, or equivalent third-party certification. Broader launch requires further legal, privacy, and security review.
Beta limitations are part of the trust posture.
Folvern is not yet positioned as a regulated-data system or enterprise-certified platform. The beta is appropriate for founder-supervised evaluation, not unattended high-risk production use.
Trust Center FAQs.
Honest answers for prospects reviewing Folvern before account creation.
Does Folvern have SOC 2, ISO 27001, HIPAA, or GDPR certification?
No. Folvern does not currently claim SOC 2, ISO 27001, HIPAA, GDPR certification, or any equivalent third-party certification. Compliance review is part of the roadmap before broader public launch.
Can I store regulated sensitive data during beta?
No, not unless your organization has completed its own compliance review and explicitly accepts the risk. Founder-supervised beta is intended for operational workflow validation.
How is customer workspace data separated?
Folvern uses organization membership, authenticated sessions, role-aware behavior, and Supabase row-level security to scope records by tenant.
What happens if there is an incident?
During beta, incidents are handled through founder-supervised support and documented response procedures. Formal public incident communication and SLA commitments are planned later.
Are backups automatic?
A fresh production database backup has been verified and restored successfully to a separate target. Folvern still does not promise a recovery time or unsupported automatic-backup behavior.
Review trust before you request access.
If your team is comfortable with the current beta boundaries, request access and test Folvern with one real operating signal.