Trust
Security
Last updated 21 September 2026
Cofoundy holds the memory of your company: decisions, documents, numbers. This page explains, without marketing, how that memory is protected — and how to reach us if you find something we missed.
01Principles
Your partners only work because you trust them with the company. Four rules shape every decision we make about security:
- You stay the founder. Partners propose; nothing is sent, published or spent without your explicit approval.
- Your memory is yours. Company context is never used to train models for other customers, and is never sold.
- Least exposure. Sensitive files can be read where they live instead of uploaded; access to anything can be revoked and takes effect on the next session.
- Nothing hidden. Every read of a file or memory thread is logged, and the trail is yours to export.
02Encryption
- In transit: all traffic uses TLS 1.2 or higher; HTTP is redirected to HTTPS and HSTS is enforced.
- At rest: databases, file storage and backups are encrypted with AES-256, with keys managed by our cloud provider's key-management service and rotated on a schedule.
- Secrets and connected-account tokens are stored in a dedicated secrets manager, never in application code or logs.
03Tenant isolation and memory
Each company's memory — the root context, partner threads, the knowledge base and the access record — is scoped to that company at the data layer. Every query carries the tenant; there is no path by which one company's partner can read another's memory.
The private and shared stores of the knowledge base are independent. A private file cannot be reached through a shared link, and moving something from private to shared is a deliberate action you take, never a default.
04Access control
- Sign-in supports single sign-on and multi-factor authentication; MFA will be required for workspace owners.
- Role-based permissions inside a workspace decide who can see which files, threads and briefings.
- Cofoundy staff do not have standing access to customer memory. Support access is granted per case, time-limited, logged, and only with your permission.
- Connected tools (email, calendar, documents, code hosting) use OAuth with the narrowest scopes each integration needs. You can disconnect any of them at any time and tokens are revoked immediately.
05Desktop sync
The desktop companion reads contracts, cap tables, spreadsheets and decks from your machine so partners can reason over them in-session. The files are not uploaded or copied to our servers unless you explicitly upload them. The companion runs with the permissions of your user account, requests folder access explicitly, and lists every path it can read in its settings.
06AI model providers
Partners are powered by third-party foundation models. We use enterprise agreements under which prompts and outputs are not used to train the provider's models and are not retained beyond what is needed to serve the request (zero-retention where the provider offers it). Only the context a partner needs for the task at hand is sent, never your whole memory.
07Audit trail
Every time a partner opens a file or loads a memory thread, that access is recorded: what, when, by which partner, for which task. You can trace any output back to the documents that informed it, and export the full record. Revoking access to a file removes it from active context on the next session.
08Infrastructure and operations
- Hosted on a major cloud provider with SOC 2 and ISO 27001 certified data centres; region selection (EU/US) is planned for general availability.
- Infrastructure is defined as code, changes go through peer review, and production deploys are automated and logged.
- Encrypted backups are taken daily and restore procedures are tested. Deleted data is purged from backups within 30 days.
- Dependencies are scanned continuously and patched on a defined schedule; critical vulnerabilities are addressed as a priority.
- Centralised logging and alerting cover authentication events, permission changes and anomalous access.
09People and process
- Everyone at Cofoundy completes security and privacy training on joining and annually.
- Access to production is limited to named engineers, protected by hardware keys, and reviewed quarterly.
- Devices are managed: full-disk encryption, automatic updates and screen lock are enforced.
- We are working toward SOC 2 Type II and will publish the report to customers under NDA when complete.
10Incident response
We maintain an incident-response plan covering detection, containment, eradication and recovery. If an incident affects your data we will notify you without undue delay and, where the law requires, within 72 hours of becoming aware — with what happened, what data was involved, what we have done and what you should do.
11Report a vulnerability
If you believe you've found a security issue in Cofoundy, email security@cofoundy.ai. Please include enough detail to reproduce it and give us reasonable time to fix it before disclosing publicly. We will acknowledge your report within two business days, keep you updated, and credit you if you wish. We will not take legal action against good-faith research that respects users' privacy and does not degrade the Service.
12Contact
Security questions, questionnaires and sub-processor lists: security@cofoundy.ai.