Read-only by design
Fallow requests minimum read scopes. It never deprovisions users or changes permissions in MVP.
Security
Fallow is designed to minimise what it collects, isolate every workspace and prevent support or engineering operators from reading tenant user data.
Fallow requests minimum read scopes. It never deprovisions users or changes permissions in MVP.
Raw scan data stays in encrypted regional blob storage and never enters Postgres.
Every request is authenticated, workspace-scoped and protected by central plan gates.
Support and engineering tooling expose metadata only—never your customer user data.
Data path
Sensitive source data is envelope-encrypted before storage. Postgres receives derived metrics and tenant-salted PII hashes—not raw API responses.
Controls
Fallow does not rely on a privacy policy alone. Its architecture removes common paths to accidental customer-data exposure.
Workspaces select a region at signup. Database, blob storage and key management stay mapped to that region.
Each workspace has an Azure Key Vault key that wraps short-lived data encryption keys.
Every report link is scoped to one file and one user, then expires after 15 minutes.
Append-only audit events form a SHA-256 hash chain; updates and deletes are rejected.
Logging and error reporting scrub credentials, tokens and customer PII before events leave the process.
Find the fallow seats
Join the private preview to evaluate the Microsoft-first workflow as production controls become available.