Trust centre

The detail behind our security claims.

A public summary of how Fallow handles tenant data, isolates workspaces and limits internal access. Formal assurance documents will be published here as they become available.

AU

Australia is the launch data region.

1:1Tenant to Key Vault key isolation
15mReport link expiry
30–90dRaw scan retention

Contact expectation

Security requests have a clear response target.

Security requests route to the Fallow security owner, who aims to acknowledge them within two business days. Please do not send credentials, secrets, exports or customer user data.

Architecture

Controls that are difficult to bypass.

Security-sensitive choices are centralised in the product architecture rather than left to individual routes or support procedures. The controls described here include target architecture and are not all generally available yet.

01

Data residency

Launch workspaces use Australian infrastructure: Neon in Sydney and Azure services in Australia East. EU and US mappings are designed but not represented as generally available at launch.

02

Per-tenant encryption

OAuth tokens and raw scan data use envelope encryption with tenant data keys wrapped by a workspace-specific Azure Key Vault key.

03

Data minimisation

Raw API responses never enter Postgres. Postgres stores derived metrics and tenant-salted hashes where possible.

04

Operator boundaries

Support and engineering tooling expose workspace metadata only. Fallow has no tenant impersonation mode.

05

Tamper evidence

Audit events are append-only and linked by a SHA-256 hash chain. Updates and deletes are rejected by database triggers.

06

Controlled egress

Reports are encrypted at rest and served only through signed, single-file URLs with a 15-minute expiry.

Sub-processors

A short, intentional list.

These providers support Fallow infrastructure and service delivery. Contractual details can be supplied during vendor review.

01

Microsoft Azure

Compute, queue, encrypted blob storage and Key Vault key management.

02

Neon

Regional serverless Postgres for application and audit metadata.

03

Stripe

Planned payment and tax provider for a future commercial launch; not enabled for the current private preview.

04

Resend

Transactional service email.

05

Cloudflare

DNS, CDN and perimeter delivery services.

Find the fallow seats

Reviewing Fallow for a vendor assessment?

Read the security overview and ask a question. The capabilities and controls described in this trust centre include target architecture and are not all generally available yet.