Trust & Security
Where Your Data Lives, and Who Can Touch It
Every claim on this page is checked directly against the running infrastructure and the product's own privacy documentation, not aspirational copy -- each one links (in a hidden citation) to its source in the codebase. If something isn't listed here, treat it as not yet verified, not as "probably fine."
Data Residency
Production infrastructure -- the database, uploaded documents, and application traffic -- runs in AWS's ca-central-1 (Canada Central) region. The prior US region's database and document bucket have both been fully decommissioned; no data remains outside Canada in either.
Encryption
- At rest: the production database (RDS) has storage encryption enabled. Uploaded documents in S3 are encrypted by default at the bucket level, and the application also sets server-side encryption explicitly on every upload.
- In transit: the application load balancer only accepts TLS 1.2 and 1.3 (AWS's `ELBSecurityPolicy-TLS13-1-2-2021-06` policy) -- no plaintext HTTP to the app.
Access Controls
- Optional two-factor authentication (TOTP authenticator apps) is available on every account, in addition to a bcrypt-hashed password or Google sign-in.
- The application is fronted by AWS WAF, running AWS's managed core rule set, a known-bad-inputs rule set, and a per-IP rate limit, in front of the app's own login/2FA rate limiting.
- AWS GuardDuty (threat detection) and CloudTrail (account-level audit logging) are enabled on the AWS account running production infrastructure.
Subprocessors
Fjord IQ uses the following subprocessors. None of them receive raw payment card data, and none are permitted to sell or use your data to train their own general-purpose models without permission.
| Subprocessor | Purpose | What they receive |
|---|---|---|
| Anthropic | AI-assisted classification, gap analysis, document generation | Document text, device descriptions, and questionnaire answers needed for a given AI call |
| Voyage AI | Regulatory-corpus search (embeddings) | The text of each search query built from your device information |
| Amazon Web Services | Hosting (database, file storage, compute) | Everything -- the underlying infrastructure provider |
| Stripe | Subscription billing | Name, email, payment details (Fjord IQ never sees raw card data) |
| Resend | Transactional email (verification, password reset, alerts) | Recipient email address and email content |
| PostHog | Product usage analytics | Product usage events -- never document content or device descriptions |
Anthropic and Voyage AI are US-hosted APIs with no regional-hosting option; PostHog's default ingestion endpoint is also US-based. Formal Data Processing Agreements with Resend and PostHog are an open item as of this writing. Full detail, including retention windows and what happens to each category of data on account deletion, is in the product's Privacy Policy.
Data Isolation Between Customers
Every request for project or document data is scoped to the authenticated founder's own account at the application level. This is enforced in application code and covered by automated tests, not by database-level row-level security -- a materially different (and weaker) guarantee than "architecturally impossible," stated plainly here rather than overclaimed.
Vulnerability Reporting
Fjord IQ does not currently operate a formal vulnerability disclosure program or a published security.txt file. If you believe you've found a security issue, please email support@fjordiq.ai with details -- reports are read directly by the founder.
This is stated plainly rather than implied: there is no bug bounty and no committed disclosure-response SLA today.
Questions
For anything not covered here -- including a request for a Data Processing Agreement -- email support@fjordiq.ai. A DPA template is available on request.