Security & Data Protection

FDDHub by Paralex, Inc.

Security overview

Security at FDDHub

FDDHub holds franchise disclosure documents while they are still confidential, and the record that proves how they were delivered. This document describes the controls behind both, the commitments attached to them, and the evidence available under NDA.

Last updated 10 September 2026  ·  Applies to fddhub.com and FDDAdvisor

Compliance
SOC 2 Type I
audit underway
Encryption
AES-256 at rest
TLS 1.2+ in transit
Data residency
United States
Security contact
security@fddhub.com
§ 01

Program and audit status

FDDHub is undergoing a SOC 2 Type I audit. A Type I report addresses whether controls are suitably designed as of a specified date; it does not address how those controls operated over a period, which is the subject of a Type II. The report will be available under NDA once issued. We do not describe FDDHub as SOC 2 certified before that point.

Framework
SOC 2 Type I — Security
Assurance covered
Design of controls as of a point in time
Status
Audit underway
Information security policies
15, approved 7 Sept 2026, reviewed annually
Continuous control monitoring
Vanta
Report access
Under NDA, on request
§ 02

Client data isolation

A firm holds many clients' disclosure data in one place. Isolation, access control and an unalterable record are the foundation of how that data is handled.

i.

Per-client isolation

Row-level security walls each client's data off from every other. A firm operates across clients, but no client's records are ever visible to another.

ii.

Encryption, in transit & at rest

All data is encrypted over TLS in transit and encrypted at rest in the database. Nothing moves or sits in the clear.

iii.

Multi-factor authentication

MFA on firm and franchisor accounts, so access to disclosure data is protected by more than a password.

iv.

Granted, revocable access

Delegate access is granted per client and revocable at any time, with every grant and revocation recorded. Access ends cleanly when an engagement does.

v.

Immutable audit trail

Every disclosure event is written to an append-only log that cannot be altered after the fact — the same record that makes a disclosure reconstructable on demand.

vi.

Durable recordkeeping

Disclosure records are retained as a permanent, tamper-evident chain — built for the recordkeeping the FTC Franchise Rule and state law expect.

§ 03

Scope of what FDDHub holds

FDDHub does not integrate with a firm's existing IT systems or tools. It runs as a self-contained system of record, so adopting it adds no new connection into that environment.

No attorney-client communications are passed through or stored in the platform. FDDHub holds the disclosure record — registration, distribution, dating, receipts, audit trail — and nothing privileged.

§ 04

Encryption and key management

Customer FDD content is classified Confidential under the Data Management Policy and handled to the same standard as FDDHub's own confidential material.

In transit
TLS 1.2+, ciphers rated B or better on SSL Labs
At rest
AES-256
Credentials
Hashed and salted — bcrypt, PBKDF2, scrypt or Argon2
Backups
Encrypted, stored apart from production data
Endpoints
Full-disk encryption, 15-minute screen lock
Removable media
Not issued or authorized — no customer data on portable media
§ 05

Internal access control

The controls in § 02 govern what customers can reach. These govern internal access by FDDHub personnel.

Default posture
Permissions not expressly granted are denied
Privileged production access
Multi-factor authentication required
Accounts
Unique per person, no shared credentials
Access reviews
Quarterly, documented
Revocation on departure
Within 24 business hours
§ 06

Infrastructure and environments

FDDHub runs entirely on managed cloud infrastructure in United States regions. There are no self-managed servers, no corporate network and no physical office.

Application & delivery
Vercel — CDN, TLS termination, platform DDoS protection
Primary datastore
Supabase (PostgreSQL) with row-level security
Document processing
Google Cloud, scoped to FDD processing projects
Environment separation
Production isolated from preview and development
Content security policy
Enforced, default-src self
§ 07

Change management

Production changes follow a single path, enforced by the platform.

Development
Feature branch, never direct to main
Validation
Isolated preview deployment before merge
Protection
Branch protection blocks direct pushes to main
Traceability
Every deploy tied to a commit SHA and logged
Rollback
Any prior deployment promotable immediately
§ 08

Vulnerability management

The external attack surface is scanned continuously and dependency advisories are monitored against the production codebase. Findings are tracked to closure against defined timelines.

External scanning
Continuous, automated
Dependency monitoring
Continuous, against the production codebase
High severity
Remediated within 60 days
Medium severity
Remediated within 120 days
Exceptions
Documented risk acceptance with a remediation plan
§ 09

Incident response

Incidents are triaged by severity and documented from first report through closure. Critical incidents receive a written root cause analysis, and counsel reviews external notices before release.

P0 — Critical
Closed within 7 days · RCA required
P1 — High
Closed within 14 days
P2 / P3 — Medium and low
Closed within 90 days
Breach notification
Without undue delay, per contract and applicable law
External notices
Reviewed and approved by counsel before release
§ 10

Business continuity and recovery

Every business system is vendor-hosted SaaS and the company is fully remote. There is no office, no on-premises hardware and no single physical location whose loss would interrupt service.

Recovery point objective
24 hours — production hosting
Recovery time objective
Defined per system in the BC/DR plan
Backup restore test
At least annually
Disaster recovery test
At least annually
Plan activation
Disruption exceeding 24 hours
§ 11

Personnel security

Personnel security requirements apply to employees and contractors alike and are conditions of access.

Screening
Background checks under the HR Security Policy
Confidentiality
Written obligations before access is granted
Policy acceptance
All 15 policies, renewed annually
Security awareness training
On joining, then annually
Offboarding
Access removed within 24 business hours
§ 12

Subprocessors

Vendors are assessed before they touch customer data, and agreements with higher-risk providers are reviewed annually.

ProviderPurposeRegion
VercelApplication hosting, CDN, edge delivery, blob storageUS
SupabasePrimary database, authentication, file storageUS
Google CloudDocument processing and storageUS
Google WorkspaceEmail and internal collaborationUS
DocuSealElectronic signature and receipt executionUS
PlausibleSite analytics — no cookies, no personal dataEU
GitHubSource control and dependency monitoringUS
IntruderExternal vulnerability scanningUK / EU
§ 13

Reporting a vulnerability

If you believe you have found a security issue in FDDHub, please report it to us before disclosing it elsewhere. We acknowledge reports within two business days and keep you updated through resolution.

security@fddhub.com

Useful reports include the affected URL or endpoint, the steps to reproduce, and what you were able to access. We will not pursue legal action against researchers who report in good faith, act in proportion to confirming the issue, and avoid accessing or altering other customers' data.

§ 14

Diligence requests

Security questionnaires, the policy set, the SOC 2 report once issued, and a signed DPA are available to customers and prospects under NDA. Write to security@fddhub.com and identify what your review requires; if you are working from a specific framework, name it and we will map to it directly.