Trust centre
How Faldaro handles your data, stated as mechanisms you can verify — never as adjectives. Each item names a behaviour, and most link to the page that spells it out. All traffic to faldaro.app and faldaro.com is served over TLS.
Isolation and access
Who can reach what
-
Tenant isolation enforced by the database
Row-level security policies in PostgreSQL match every query against the organization bound from a verified token. The application connects as a non-superuser and refuses to start if the policies would not apply. A query that loses its tenant context returns nothing, never everything.
-
Privileges from one place
Privileges are seeded once and served by the API. A role granted on an organization applies down its tree and never up or sideways, and nobody can grant a privilege they do not hold.
-
Single sign-on, passkeys and rotated sessions
OIDC against your own identity provider on Enterprise, with sessions scoped to your organization and its descendants. Passkeys and Google sign-in on every plan. Refresh tokens are rotated on every use.
-
Machine access with explicit grants
An API key carries a stated set of privileges and nothing more. The MCP server forwards your key verbatim to the same authorization stack every request passes through, and judges no credential itself.
Integrity
What cannot be quietly changed
-
Immutable published versions
Publishing a form, dataset or template creates a version that never changes. Every submission keeps the exact definition it was filled against, for as long as it exists.
-
An append-only audit log
Update and delete are revoked from the application role, so the log cannot be rewritten by the application. Every write a person can trigger lands in it under the real actor: a user, an API key, an agent, or the anonymous public surface.
-
Values the server owns
Calculated fields are recomputed on the server on every save and every read. Payment amounts are priced from the submitted answers and never accepted from a request. Formulas run in a closed evaluator with an operation budget, never in a code interpreter.
-
Budgets on untrusted input
Author-supplied patterns, report queries, document renders, uploads and public submissions each run under a bound the server enforces, so no single tenant can pin the service.
Data lifecycle
How data arrives, leaves and ends
-
Retention you can prove
Each form can carry a retention period. Submissions past it are deleted permanently on schedule, and each purge is recorded so you can show what was removed and when.
-
Export and import
Your submissions leave as CSV and come back as records with their reference numbers and workflow states. An import replays nothing: no notifications, no integrations, no freshly minted numbers.
-
Public surfaces are opt-in
A form is never reachable anonymously because it exists — only because someone with the privilege issued a tokenized link. Links are revoked by rotation, every refusal is an identical not-found, and archiving a form takes its public pages down with it.
-
Outward links carry projections, never data
Tracking pages, shared reports, the submitter portal and approval links each serve a curated projection behind a revocable token. Individual records never leave the tenant this way.
AI
The AI data path
-
Your permissions, never more
The assistant and the standing agents act inside the same authorization boundary as the person or key behind them. They have no delete tools, no administrative tools and no credentials of their own.
-
Per request, for the action you invoked
Content reaches the language-model provider only for the action you asked for, in that request. What someone outside your organization submits — through a public link, by email or over the API — is wrapped as data, never presented as instructions, before a model sees it.
-
Nothing of yours trains a model
Faldaro’s language-model features use your content for the request and nothing else. The predictive models built by Form Insights are trained only on your own organization’s records, at your request, and serve only your organization.
-
Over MCP, the model is yours
A connected model calls tools with your API key and no other credential. Faldaro meters no AI credits for the transport, because the model in the loop is the client’s.
Where it runs
Subprocessors
The services the hosted platform relies on, and what each is used for.
| Provider | Purpose |
|---|---|
| Google Cloud | Application hosting, the PostgreSQL database and object storage for uploaded files. |
| Hetzner | Web front-end hosting. |
| Anthropic | Language-model features — the assistant, inline AI, agents and insight narration — called per request. |
| Stripe | Payments collected through your forms, and subscription billing. |
| Google sign-in, for people who choose it. | |
| Cloudflare | Turnstile captcha on public forms, where the operator enables it. |
| Transactional email provider | Outbound notifications and account mail, as configured for the deployment. |
Integrations you connect yourself — Zapier, Slack, your own webhook endpoints — receive only what the rule or workflow action you authored sends, with every delivery signed.
Disclosure and reviews
Talking to us about security
-
Report a vulnerability
Email security@faldaro.com with a description, the steps to reproduce and what you were able to reach. Expect an acknowledgement within two working days and an assessment within five. Credit in the fix is offered; not being named is the default.
-
Security reviews
Questionnaires are answered in writing by the team, mechanism by mechanism, in the same register as this page. Write to sales@faldaro.com with what your review requires.
Bring your security review
Every answer is a mechanism, and every mechanism is checkable in behaviour before you commit anything.