Security

This is how Fóir protects what you store in it, stated as plainly as we can. Where something is not in place yet, this page says so.

Where your data lives

The application and its databases run in the EU, in Nuremberg, Germany.

Files you upload are stored in Cloudflare R2, in Cloudflare's Western Europe region. They are delivered through Cloudflare's network, so a file may be served from a location near the person requesting it.

Your data is separated from every other customer's

Fóir decides who can read and write each row inside the database itself, using row-level security. The usual place for that check is an API layer above the database, and that is where most platforms are weakest. Our rules are compiled from one specification by Demesne, our open-source engine, and row-level security is forced on every table the specification governs. A test lists every table in our schema and fails on any that was added without a recorded decision about how it is protected.

A check in an API layer covers only the paths someone remembered to guard. A rule inside the database also covers the paths nobody remembered, including code written later and code we write ourselves. There is more on the page about enforcement in the database.

Encryption

In transit, every external connection uses TLS.

At rest, the files you upload are encrypted by Cloudflare R2.

Secrets you store in Fóir, such as credentials for your own integrations, are encrypted with AES-256-GCM before they are written. Listing your secrets returns their names and dates. It does not return their values. The assistant and agent tools can store and list secrets, and they cannot read one back. A value is returned only to a caller that holds read permission for that secret, and every read is recorded.

Backups and recovery

Production databases are backed up continuously, with point-in-time recovery. Our targets are at most one hour of data loss and at most four hours to restore service.

We also rehearse restores.

Availability

We do not publish an uptime SLA yet. Current status and past incidents are on our status page, status.foir.io.

Reporting a vulnerability

Write to info@foir.io. Tell us what you found and how to reproduce it, and please give us the chance to fix it before you make it public.

Compliance

We are not SOC 2 certified.

We offer a Data Processing Agreement on request: write to info@foir.io. Every sub-processor we use is listed on the privacy page.