Data residency
Launch workspaces use Australian infrastructure: Neon in Sydney and Azure services in Australia East. EU and US mappings are designed but not represented as generally available at launch.
Trust centre
A public summary of how Fallow handles tenant data, isolates workspaces and limits internal access. Formal assurance documents will be published here as they become available.
Australia is the launch data region.
Architecture
Security-sensitive choices are centralised in the product architecture rather than left to individual routes or support procedures.
Launch workspaces use Australian infrastructure: Neon in Sydney and Azure services in Australia East. EU and US mappings are designed but not represented as generally available at launch.
OAuth tokens and raw scan data use envelope encryption with tenant data keys wrapped by a workspace-specific Azure Key Vault key.
Raw API responses never enter Postgres. Postgres stores derived metrics and tenant-salted hashes where possible.
Support and engineering tooling expose workspace metadata only. Fallow has no tenant impersonation mode.
Audit events are append-only and linked by a SHA-256 hash chain. Updates and deletes are rejected by database triggers.
Reports are encrypted at rest and served only through signed, single-file URLs with a 15-minute expiry.
Sub-processors
These providers support Fallow infrastructure and service delivery. Contractual details can be supplied during vendor review.
Compute, queue, encrypted blob storage and Key Vault key management.
Regional serverless Postgres for application and audit metadata.
Subscription billing, checkout and tax processing.
Transactional service email.
DNS, CDN and perimeter delivery services.
Find the fallow seats
Send your security questionnaire or architecture questions directly to the Fallow security contact.