Where we stand
Current compliance posture, stated plainly
We would rather tell you exactly where we are than imply more than we have earned. FTR42 is mid-programme on SOC 2 Type II. No audit report exists yet, and we do not claim one.
We hold no ISO 27001, HIPAA or PCI DSS attestation, and we do not represent ourselves as certified under any framework we have not completed.
01 / Governance
Eleven approved policies, plus five still in draft
Approved policies are version-controlled in Vanta and renewed on an annual cycle. Draft policies are listed so we do not pretend they are done.
Still draft: Access Control, Code of Conduct, Human Resource Security, Physical Security, Incident Response.
Risk management
We keep a risk register with inherent and residual scoring, and we run control self-assessments at least annually. Findings get an owner and a fix plan. We have no standing remediation SLA with customers unless a written SOW attaches one.
02 / Data protection
Encryption, classification and retention
Data in transit
Confidential and sensitive data is encrypted with secure transport protocols whenever it crosses a public network. This applies to our own applications and to the interfaces we build for customers.
Data at rest
Customer data resides in managed cloud platforms, principally Supabase, AWS and Vercel, which encrypt at rest as a platform default. Privileged access to encryption keys is restricted to users with a documented business need.
Classification and retention
A data classification policy defines how information is categorised and handled, and documented retention procedures govern how long we keep it. We retain information for as long as needed to operate the service or to satisfy a legitimate business or legal requirement, and no longer.
Disposal
Electronic media holding confidential information is purged or destroyed in line with recognised practice, and a certificate of destruction is issued for each device destroyed.
03 / Infrastructure
Production is separated, restricted and logged
- Production application access is restricted to authorised users only.
- Production databases (Supabase) restrict privileged access to people with a business need, using unique credentials and provider MFA where we have turned it on.
- Hosting is serverless on Vercel and managed cloud services. We do not run our own servers, SSH bastions, or a company-owned network firewall.
- Logs come from those providers and from application logs we retain for security and operations.
- Inventory of in-scope assets is tracked in Vanta. Some integrations (Google Workspace, Supabase) still need to be reconnected so that inventory stays complete.
Physical data centres are operated by our cloud providers. We do not claim their building access as a control we perform ourselves.
04 / Access control
Least privilege, enforced by tooling
Access is granted on the basis of role and business need, and removed when the need ends. Identity is centralised in Google Workspace; credentials that cannot be federated are held in a managed password manager rather than in documents or chat.
- Passwords for in-scope systems are configured according to our password policy.
- Privileged access to production consoles, databases, and encryption-key settings is separately restricted and individually justified.
- Access is reviewed on a defined cycle, and revoked as part of offboarding.
05 / Secure development
How code reaches production
We run a documented development lifecycle: GitHub for source, pull-request review on main, and Vercel for production deploys. Emergency changes still go through that path unless a documented exception is recorded.
- Vulnerability handling is an engineering duty. We do not currently publish a pentest of production or sell an intrusion-detection product to customers.
- Control self-assessments are performed at least annually, with an owner on findings.
06 / Incident response
What happens when something goes wrong
The Incident Response Plan is still in draft in Vanta. Until it is approved, reports still go to security@ftr42.com. If we confirm an incident affecting customer materials on systems we operate, we notify the affected customer without unreasonable delay, as stated in the Terms.
A Business Continuity and Disaster Recovery plan is approved. It covers how we keep operating if key people are unavailable.
If you think you found a vulnerability in something we operate, write to the address below. We will acknowledge the report and keep you informed as we work it.
07 / People
The smallest attack surface is a well-run team
FTR42 is a small, senior team, and our controls are built for that shape rather than borrowed from a larger one.
- A Code of Conduct and Human Resource Security Policy exist as drafts in Vanta. Personnel will acknowledge them once they are approved. Until then, security expectations for each role sit in the approved Information Security Policy and Roles and Responsibilities policy.
- Security responsibilities are assigned to named individuals, not left implicit.
08 / Subprocessors
Who else touches the data
We assess third parties before we adopt them and review them on a recurring basis under our Third-Party Management Policy. The providers below support delivery of our services.
| Provider | Purpose | Risk tier |
|---|---|---|
| Amazon Web Services | Cloud infrastructure, Bedrock models, Titan embeddings | Critical |
| Supabase | Application database and authentication | Critical |
| Google Workspace | Identity, email, documents | Critical |
| GitHub | Source control | Critical |
| Vercel | Application hosting | High |
| Anthropic | In-app assistant and coaching text | High |
| Apple / Google | App distribution, push, device speech-to-text | High |
| Stripe | Shop billing when the owner connects payment | High |
| Bitwarden | Credential management | High |
| Vanta | Compliance monitoring (not a ValSpark data processor for shop records) | High |
| Resend | FTR42 transactional email | - |
| Twilio | FTR42 marketing/lead SMS only; not ValSpark staff SMS | - |
Risk tiers reflect our internal inherent-risk assessment. Where a tier is not shown, the provider is in scope of our register but not yet tiered.
09 / Contact
Reporting a vulnerability, or asking for more
Security reports: security@ftr42.com
Privacy and support: scale@ftr42.com (two business days, see valspark.ai/support)
Terms: ftr42.com/terms and valspark.ai/terms
Status: ftr42.com/status (public, no login)
Updates: ftr42.com/updates (public product change log)
Prospects, customers and auditors who need more than this page (control evidence, the policy set, a questionnaire, or an NDA first) should write to us. We will route it the same week.
This page is maintained by the Security & Compliance owner named at the top, reviewed quarterly, and re-confirmed whenever our practices, audits or policies change.