Security

Customer data should stay customer data.

Fallow is designed to minimise what it collects, isolate every workspace and prevent support or engineering operators from reading tenant user data.

01

Read-only by design

Fallow requests minimum read scopes. It never deprovisions users or changes permissions in MVP.

02

Private by architecture

Raw scan data stays in encrypted regional blob storage and never enters Postgres.

03

Scoped to your workspace

Every request is authenticated, workspace-scoped and protected by central plan gates.

04

No operator visibility

Support and engineering tooling expose metadata only—never your customer user data.

Data path

Encrypt early. Expose less. Expire automatically.

Sensitive source data is envelope-encrypted before storage. Postgres receives derived metrics and tenant-salted PII hashes—not raw API responses.

01Read-only APIMinimum scopes
02EncryptTenant data key
03DeriveMetrics + hashes
04Expire30–90 day TTL

Controls

Security choices that reduce the blast radius.

Fallow does not rely on a privacy policy alone. Its architecture removes common paths to accidental customer-data exposure.

01

Regional storage

Workspaces select a region at signup. Database, blob storage and key management stay mapped to that region.

02

Per-tenant keys

Each workspace has an Azure Key Vault key that wraps short-lived data encryption keys.

03

Signed downloads

Every report link is scoped to one file and one user, then expires after 15 minutes.

04

Tamper-evident history

Append-only audit events form a SHA-256 hash chain; updates and deletes are rejected.

05

No secrets in telemetry

Logging and error reporting scrub credentials, tokens and customer PII before events leave the process.

Find the fallow seats

Review access without widening access to your review data.

Join the private preview to evaluate the Microsoft-first workflow as production controls become available.