Security
How assessment data is protected in transit, at rest, and in access control.
Last updated 1 August 2026
Access control
Authorization is enforced by row-level security policies in the database. A founder's rows are reachable only by that founder; an organization reaches a founder only through an explicit commissioning record; raw answers are never exposed to organizations at all.
Encryption
All traffic is served over TLS. Data at rest is encrypted by the database provider, and sensitive fields are additionally protected from access by application roles that do not require them.
Payments
Card details are handled entirely by our payment providers and never reach our servers. We store only the provider reference, the amount, and the status.
Auditing
Administrative actions are written to an append-only audit log recording the actor, the action, the affected record and the time. Report vulnerabilities to security@founderdna.ai.