Security & compliance

Built to satisfy the compliance team.

Every change, export, and admin action is written to an append only log you can export any time. Firms are isolated at the data layer, so your clients’ numbers never sit next to another firm’s.

Encrypted in transit
TLS 1.2+ · HSTS preloaded
Encrypted at rest
AES-256 via Neon Postgres
Firm level isolation
Every query scoped by firm ID, tested
Append only audit log
Security events kept seven years

Audit log — live

TimeEventActor
  • 04:22:18Edited eventSusan retires · 2040 → 2041rachel@linden-moss.com
  • 04:22:04Recalc complete1,000 trialssystem
  • 04:21:57Exported PDFhewitt-annual-review.pdfrachel@linden-moss.com
  • 04:19:33Imported document1099-B · schwab-2024.pdfalex@linden-moss.com
  • 04:14:02Deleted accountSchwab · brokerage ···4471rachel@linden-moss.com
Controls

Six controls that protect your clients’ financial lives.

The same plan can carry a family’s numbers for decades. These are the measures that keep that data private, isolated, and recoverable.

01 / 06

Encrypted in transit and at rest

Traffic runs over HTTPS with TLS 1.2 or higher, and HSTS is preloaded across every subdomain. Data sits encrypted at rest with AES-256 in Neon managed Postgres. Hardened response headers — deny framing, block MIME sniffing, cross origin isolation — ship on every request.

02 / 06

Authentication and least privilege access

Identity, sessions, and multifactor are managed by Clerk, and MFA is required for firm administrators. Access is role based and enforced on the server for every action, never just hidden in the interface.

03 / 06

One firm's data never touches another's

Every client data query is scoped by firm ID at the data layer. Automated isolation tests run across all API routes on every build, and responses are never edge cached — so one firm's numbers can't surface in another firm's session.

04 / 06

Read only access. No money movement.

Clients link accounts from their own portal, authenticating with their bank through Plaid — Foundry never sees or stores bank credentials, only an encrypted access token. Access is read only: balances, holdings, transactions, liabilities. Foundry requests no payment or transfer permission and cannot move money in, out, or between accounts. Clients can unlink an institution at any time.

05 / 06

Continuous monitoring and review

Dependencies are scanned on every build, security relevant changes are reviewed before they merge, and disclosed vulnerabilities are triaged on a fixed clock. Sentry watches errors and performance in production with client PII redacted.

06 / 06

Backups, recovery, and residency

Application data lives in US regions on Neon managed Postgres with point in time recovery. Incidents follow a documented runbook with on call response. Nothing about recovery depends on a single machine staying up.

Subprocessors

The vendors that touch your data, and what they answer to.

We name every third party that processes customer data, and we obtain and review each vendor’s current SOC 2 / ISO attestation.

VendorWhat it handlesCertifications
StripePayments & billingPCI DSS Level 1 · SOC 2 Type II · ISO 27001
ClerkAuthentication & MFASOC 2 Type II
PlaidBank & brokerage account linkingSOC 2 Type II · ISO 27001 · ISO 27701
NeonManaged Postgres — your dataSOC 2 Type II · ISO 27001 · HIPAA eligible
VercelHosting & edge runtimeSOC 2 Type II · ISO 27001
SentryError & performance monitoringSOC 2 Type II · ISO 27001 · HIPAA eligible
UpstashRate limiting cacheSOC 2 Type II
ResendTransactional email deliverySOC 2 Type II
Azure OpenAIDocument extraction (AI Import)SOC 1/2/3 · ISO 27001/27017/27018/27701

No model training.Documents uploaded for AI Import are never used to train models.

30 days’ notice. Written notice to your owner of record before we add or replace any subprocessor that handles client data. You may object on reasonable grounds during that window.

US data residency. Application data is stored in US regions.

Full subprocessor list and our Data Processing Addendum live in the DPA.Last reviewed: 2026-07-18

Responsible disclosure

Found a security issue? Tell us and we’ll get on it. We respond to every good faith report and won’t pursue researchers who act in good faith.

security@foundryplanning.com
Build a plan on the call

Bring a real client. We’ll build their plan on the call.

A live Zoom session where we build a working plan together. Bring a brokerage statement, a tax return, or a list of constraints — redact the names if you like; the plan builds the same. The data goes in fast and we plan in front of you.

Call duration
~30 min
Preparation
Zero
Cost
Free
Demo requestFF-0000

We reply within one business day with a calendar link.