- Compliance
- SOC 2 Type I
audit underway - Encryption
- AES-256 at rest
TLS 1.2+ in transit - Data residency
- United States
- Security contact
- security@fddhub.com
Program and audit status
FDDHub is undergoing a SOC 2 Type I audit. A Type I report addresses whether controls are suitably designed as of a specified date; it does not address how those controls operated over a period, which is the subject of a Type II. The report will be available under NDA once issued. We do not describe FDDHub as SOC 2 certified before that point.
- Framework
- SOC 2 Type I — Security
- Assurance covered
- Design of controls as of a point in time
- Status
- Audit underway
- Information security policies
- 15, approved 7 Sept 2026, reviewed annually
- Continuous control monitoring
- Vanta
- Report access
- Under NDA, on request
Client data isolation
A firm holds many clients' disclosure data in one place. Isolation, access control and an unalterable record are the foundation of how that data is handled.
Per-client isolation
Row-level security walls each client's data off from every other. A firm operates across clients, but no client's records are ever visible to another.
Encryption, in transit & at rest
All data is encrypted over TLS in transit and encrypted at rest in the database. Nothing moves or sits in the clear.
Multi-factor authentication
MFA on firm and franchisor accounts, so access to disclosure data is protected by more than a password.
Granted, revocable access
Delegate access is granted per client and revocable at any time, with every grant and revocation recorded. Access ends cleanly when an engagement does.
Immutable audit trail
Every disclosure event is written to an append-only log that cannot be altered after the fact — the same record that makes a disclosure reconstructable on demand.
Durable recordkeeping
Disclosure records are retained as a permanent, tamper-evident chain — built for the recordkeeping the FTC Franchise Rule and state law expect.
Scope of what FDDHub holds
FDDHub does not integrate with a firm's existing IT systems or tools. It runs as a self-contained system of record, so adopting it adds no new connection into that environment.
No attorney-client communications are passed through or stored in the platform. FDDHub holds the disclosure record — registration, distribution, dating, receipts, audit trail — and nothing privileged.
Encryption and key management
Customer FDD content is classified Confidential under the Data Management Policy and handled to the same standard as FDDHub's own confidential material.
- In transit
- TLS 1.2+, ciphers rated B or better on SSL Labs
- At rest
- AES-256
- Credentials
- Hashed and salted — bcrypt, PBKDF2, scrypt or Argon2
- Backups
- Encrypted, stored apart from production data
- Endpoints
- Full-disk encryption, 15-minute screen lock
- Removable media
- Not issued or authorized — no customer data on portable media
Internal access control
The controls in § 02 govern what customers can reach. These govern internal access by FDDHub personnel.
- Default posture
- Permissions not expressly granted are denied
- Privileged production access
- Multi-factor authentication required
- Accounts
- Unique per person, no shared credentials
- Access reviews
- Quarterly, documented
- Revocation on departure
- Within 24 business hours
Infrastructure and environments
FDDHub runs entirely on managed cloud infrastructure in United States regions. There are no self-managed servers, no corporate network and no physical office.
- Application & delivery
- Vercel — CDN, TLS termination, platform DDoS protection
- Primary datastore
- Supabase (PostgreSQL) with row-level security
- Document processing
- Google Cloud, scoped to FDD processing projects
- Environment separation
- Production isolated from preview and development
- Content security policy
- Enforced, default-src self
Change management
Production changes follow a single path, enforced by the platform.
- Development
- Feature branch, never direct to main
- Validation
- Isolated preview deployment before merge
- Protection
- Branch protection blocks direct pushes to main
- Traceability
- Every deploy tied to a commit SHA and logged
- Rollback
- Any prior deployment promotable immediately
Vulnerability management
The external attack surface is scanned continuously and dependency advisories are monitored against the production codebase. Findings are tracked to closure against defined timelines.
- External scanning
- Continuous, automated
- Dependency monitoring
- Continuous, against the production codebase
- High severity
- Remediated within 60 days
- Medium severity
- Remediated within 120 days
- Exceptions
- Documented risk acceptance with a remediation plan
Incident response
Incidents are triaged by severity and documented from first report through closure. Critical incidents receive a written root cause analysis, and counsel reviews external notices before release.
- P0 — Critical
- Closed within 7 days · RCA required
- P1 — High
- Closed within 14 days
- P2 / P3 — Medium and low
- Closed within 90 days
- Breach notification
- Without undue delay, per contract and applicable law
- External notices
- Reviewed and approved by counsel before release
Business continuity and recovery
Every business system is vendor-hosted SaaS and the company is fully remote. There is no office, no on-premises hardware and no single physical location whose loss would interrupt service.
- Recovery point objective
- 24 hours — production hosting
- Recovery time objective
- Defined per system in the BC/DR plan
- Backup restore test
- At least annually
- Disaster recovery test
- At least annually
- Plan activation
- Disruption exceeding 24 hours
Personnel security
Personnel security requirements apply to employees and contractors alike and are conditions of access.
- Screening
- Background checks under the HR Security Policy
- Confidentiality
- Written obligations before access is granted
- Policy acceptance
- All 15 policies, renewed annually
- Security awareness training
- On joining, then annually
- Offboarding
- Access removed within 24 business hours
Subprocessors
Vendors are assessed before they touch customer data, and agreements with higher-risk providers are reviewed annually.
| Provider | Purpose | Region |
|---|---|---|
| Vercel | Application hosting, CDN, edge delivery, blob storage | US |
| Supabase | Primary database, authentication, file storage | US |
| Google Cloud | Document processing and storage | US |
| Google Workspace | Email and internal collaboration | US |
| DocuSeal | Electronic signature and receipt execution | US |
| Plausible | Site analytics — no cookies, no personal data | EU |
| GitHub | Source control and dependency monitoring | US |
| Intruder | External vulnerability scanning | UK / EU |
Reporting a vulnerability
If you believe you have found a security issue in FDDHub, please report it to us before disclosing it elsewhere. We acknowledge reports within two business days and keep you updated through resolution.
security@fddhub.comUseful reports include the affected URL or endpoint, the steps to reproduce, and what you were able to access. We will not pursue legal action against researchers who report in good faith, act in proportion to confirming the issue, and avoid accessing or altering other customers' data.
Diligence requests
Security questionnaires, the policy set, the SOC 2 report once issued, and a signed DPA are available to customers and prospects under NDA. Write to security@fddhub.com and identify what your review requires; if you are working from a specific framework, name it and we will map to it directly.