← Back to Fjord IQ

Trust & Security

Where Your Data Lives, and Who Can Touch It

Every claim on this page is checked directly against the running infrastructure and the product's own privacy documentation, not aspirational copy -- each one links (in a hidden citation) to its source in the codebase. If something isn't listed here, treat it as not yet verified, not as "probably fine."

Data Residency

Production infrastructure -- the database, uploaded documents, and application traffic -- runs in AWS's ca-central-1 (Canada Central) region. The prior US region's database and document bucket have both been fully decommissioned; no data remains outside Canada in either.

Encryption

Access Controls

Subprocessors

Fjord IQ uses the following subprocessors. None of them receive raw payment card data, and none are permitted to sell or use your data to train their own general-purpose models without permission.

SubprocessorPurposeWhat they receive
AnthropicAI-assisted classification, gap analysis, document generationDocument text, device descriptions, and questionnaire answers needed for a given AI call
Voyage AIRegulatory-corpus search (embeddings)The text of each search query built from your device information
Amazon Web ServicesHosting (database, file storage, compute)Everything -- the underlying infrastructure provider
StripeSubscription billingName, email, payment details (Fjord IQ never sees raw card data)
ResendTransactional email (verification, password reset, alerts)Recipient email address and email content
PostHogProduct usage analyticsProduct usage events -- never document content or device descriptions

Anthropic and Voyage AI are US-hosted APIs with no regional-hosting option; PostHog's default ingestion endpoint is also US-based. Formal Data Processing Agreements with Resend and PostHog are an open item as of this writing. Full detail, including retention windows and what happens to each category of data on account deletion, is in the product's Privacy Policy.

Data Isolation Between Customers

Every request for project or document data is scoped to the authenticated founder's own account at the application level. This is enforced in application code and covered by automated tests, not by database-level row-level security -- a materially different (and weaker) guarantee than "architecturally impossible," stated plainly here rather than overclaimed.

Vulnerability Reporting

Fjord IQ does not currently operate a formal vulnerability disclosure program or a published security.txt file. If you believe you've found a security issue, please email support@fjordiq.ai with details -- reports are read directly by the founder.

This is stated plainly rather than implied: there is no bug bounty and no committed disclosure-response SLA today.

Questions

For anything not covered here -- including a request for a Data Processing Agreement -- email support@fjordiq.ai. A DPA template is available on request.