UK GDPR · Article 32 aligned

    Security & Compliance

    We take the protection of your data seriously. This page summarises the technical and organisational measures we have in place to keep your information confidential, available, and resilient.

    Our operating model

    Fractional Founders is a UK-based remote-first organisation. We do not operate a physical office that processes customer data. All production data is held by vetted sub-processors in tier-IV-class data centres under SOC 2 and ISO 27001 attestations, and accessed by personnel from hardened, encrypted devices.

    Our data protection measures

    Fractional Founders operates a serverless web platform hosted on managed UK/EU infrastructure. The following controls protect data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure.

    Encryption

    All data is encrypted at rest with AES-256 (exceeding the AES-128 minimum) and in transit with TLS 1.2+. Secrets are stored in a managed vault and never exposed to the browser.

    Access Control (RBAC)

    Role-based access control enforced at the database layer via Row-Level Security. Roles (admin, viewer, expert, client) live in a dedicated table and are validated by a security-definer function on every query.

    Pseudonymisation

    Users are referenced by non-sequential UUIDs. Public-facing views strip emails and direct identifiers. Sensitive tables are protected by RESTRICTIVE policies, accessible only to authenticated admins.

    Resilience & Backups

    Multi-AZ managed infrastructure with automated daily backups and 7-day point-in-time recovery. Storage replicated across availability zones with 99.999999999% durability.

    Monitoring & Incident Response

    Centralised logging, activity audit logs for sensitive actions, continuous security scanning, and rate-limited public endpoints. Reportable breaches are notified to the ICO within 72 hours per UK GDPR Article 33.

    Testing & Assurance

    Automated database security scans, dependency vulnerability checks, and annual review of RLS policies, authentication flows, and disaster-recovery procedures.

    Physical & environmental security

    Physical security & data centres

    Because we have no on-premises production environment, physical security is delivered primarily through our sub-processors. The controls below describe both their inherited protections and our own endpoint and asset controls.

    Data centres (via sub-processors)

    Production data is hosted exclusively in tier-IV-class facilities operated by AWS (via Supabase), Cloudflare, Resend and Calendly. Perimeter fencing, 24/7 guarding, CCTV, biometric/badge access, redundant power and cooling, and fire suppression are inherited from their SOC 2 and ISO 27001 attestations (available on request).

    Asset management & classification

    All company-issued devices are inventoried. Data is classified as Public, Internal, Confidential or Restricted; customer personal data is treated as Confidential or Restricted by default and only handled on managed endpoints.

    Secure destruction

    Cloud storage is securely erased via provider cryptographic erase (NIST SP 800-88 aligned, via AWS). Retired laptops are wiped to NIST SP 800-88 Purge level before resale or certified recycling.

    Visitor control

    Fractional Founders operates remote-first with no physical office processing customer data, so visitor control at our own premises is not applicable. Visitor controls at sub-processor data centres are covered by their published SOC 2 / ISO 27001 reports.

    Endpoint controls

    Full-disk encryption (FileVault / BitLocker), automatic OS updates, screen-lock, strong passcodes and reputable endpoint protection are required on every device. Production data is never stored locally.

    People

    Information security training & awareness

    Our people are the first line of defence. Everyone working with customer data completes training and accepts the policies that govern how it must be handled.

    Induction

    Every joiner receives a security and data-protection briefing covering UK GDPR basics, phishing, password hygiene, device security and incident reporting before being granted access.

    Annual refresher

    Policies and the current threat landscape are reviewed with all personnel at least annually, with ad-hoc updates when significant risks emerge.

    Phishing awareness

    Personnel are trained to recognise and report suspicious messages. A clear internal reporting channel is published and reviewed.

    Policy acknowledgement

    Written acceptance of our Acceptable Use, Information Security and Data Protection policies is required from all staff and contractors.

    Contractual obligations

    Confidentiality and data-protection clauses appear in every staff, contractor and expert agreement. Obligations flow down to sub-processors via Data Processing Agreements.

    Vetting

    Personnel security & vetting

    We verify the people who deliver our services and tightly control their access to customer data across the joiner, mover and leaver lifecycle.

    Identity & right to work

    Identity and right-to-work are verified for all staff and contractors before any access to systems or customer data is granted.

    Reference checks

    Experts joining our network complete a structured two-referee workflow. Staff hires complete standard professional reference checks.

    Confidentiality & IP clauses

    Robust confidentiality and intellectual property clauses are included in every staff and expert agreement and survive termination.

    Joiners, movers & leavers

    Least-privilege access is provisioned on joining, reviewed on role change, and fully revoked on leaving — including portal account deletion via our existing cascading-delete flow.

    Enhanced checks where required

    DBS or equivalent disclosure checks are obtained where a specific engagement requires them (for example, work involving children, vulnerable adults or regulated sectors). They are not applied by default, as most engagements do not require them.

    Supply chain transparency

    Sub-processors

    We use a small set of carefully selected providers to deliver our service. Each one is bound by a Data Processing Agreement and only receives the minimum data necessary to perform its function.

    ProviderPurposeRegionCompliance
    Lovable Cloud (Supabase / AWS)Database, authentication, object storage, edge functionsEU / UKSOC 2, ISO 27001 (via AWS)
    ResendTransactional email deliveryEU / USGDPR, DPA in place
    CalendlyStrategy Session schedulingUS (SCCs)GDPR, DPA in place
    CloudflareCDN, DDoS protection, edge deliveryGlobalSOC 2, ISO 27001

    Your data rights

    Under UK GDPR you have the right to access, rectify, erase, restrict, port, or object to the processing of your personal data. Contact us at any time to exercise these rights.

    Report a security issue

    If you believe you have found a security vulnerability, please disclose it responsibly by emailing us. We will acknowledge within 2 business days.

    hello@fractionalfounders.co.uk

    Need our full Technical & Organisational Measures document for a vendor assessment?

    Request TOMs document

    Last reviewed: July 2026

    Cookie Preferences

    We use cookies to enhance your experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. Learn more