Security & Compliance
This page describes the technical and organisational measures we have in place today, and where we are honest that a formal certification does not yet exist. If you need documentation for a security review, contact us at [email protected].
Encryption in transit
All traffic to and from FusionPointAI is served over HTTPS/TLS. We publish a Content Security Policy and standard browser security headers (X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy) on every page.
Access control
Staff access follows a role-based hierarchy with least-privilege defaults: each admin role can only see and manage accounts at or below its own level. Every privileged action - impersonating a customer, changing a role, editing a record on another team's behalf - is written to an append-only audit log that cannot be edited or deleted after the fact.
Multi-factor authentication
MFA is mandatory for every administrator, support, and privileged staff account. Customers can enable optional two-factor authentication on their own account from their dashboard security settings.
Abuse and bot protection
Authentication and account-creation endpoints are rate-limited and protected by Cloudflare Turnstile. Sensitive administrative routes carry their own dedicated rate limits.
Backups
The production database is backed up on a regular automated schedule. We are still in the process of moving that backup to off-site storage and cannot yet claim geographic redundancy - this is on our roadmap.
Incident response
If we become aware of a security incident affecting your data, we will notify affected customers without undue delay once the incident is understood, along with what we know and what we are doing about it.
Certifications and penetration testing
We do not currently hold a SOC 2 or ISO 27001 certification, and we do not yet run penetration tests on a fixed, published cadence. Both are on our roadmap. If a certification or a specific test result is a requirement for your procurement process, contact us at [email protected] to discuss your timeline.