Security & Compliance
We take the protection of your data seriously. This page summarises the technical and organisational measures we have in place to keep your information confidential, available, and resilient.
Our operating model
Fractional Founders is a UK-based remote-first organisation. We do not operate a physical office that processes customer data. All production data is held by vetted sub-processors in tier-IV-class data centres under SOC 2 and ISO 27001 attestations, and accessed by personnel from hardened, encrypted devices.
Our data protection measures
Fractional Founders operates a serverless web platform hosted on managed UK/EU infrastructure. The following controls protect data against accidental or unlawful destruction, loss, alteration, or unauthorised disclosure.
Encryption
All data is encrypted at rest with AES-256 (exceeding the AES-128 minimum) and in transit with TLS 1.2+. Secrets are stored in a managed vault and never exposed to the browser.
Access Control (RBAC)
Role-based access control enforced at the database layer via Row-Level Security. Roles (admin, viewer, expert, client) live in a dedicated table and are validated by a security-definer function on every query.
Pseudonymisation
Users are referenced by non-sequential UUIDs. Public-facing views strip emails and direct identifiers. Sensitive tables are protected by RESTRICTIVE policies, accessible only to authenticated admins.
Resilience & Backups
Multi-AZ managed infrastructure with automated daily backups and 7-day point-in-time recovery. Storage replicated across availability zones with 99.999999999% durability.
Monitoring & Incident Response
Centralised logging, activity audit logs for sensitive actions, continuous security scanning, and rate-limited public endpoints. Reportable breaches are notified to the ICO within 72 hours per UK GDPR Article 33.
Testing & Assurance
Automated database security scans, dependency vulnerability checks, and annual review of RLS policies, authentication flows, and disaster-recovery procedures.
Physical security & data centres
Because we have no on-premises production environment, physical security is delivered primarily through our sub-processors. The controls below describe both their inherited protections and our own endpoint and asset controls.
Data centres (via sub-processors)
Production data is hosted exclusively in tier-IV-class facilities operated by AWS (via Supabase), Cloudflare, Resend and Calendly. Perimeter fencing, 24/7 guarding, CCTV, biometric/badge access, redundant power and cooling, and fire suppression are inherited from their SOC 2 and ISO 27001 attestations (available on request).
Asset management & classification
All company-issued devices are inventoried. Data is classified as Public, Internal, Confidential or Restricted; customer personal data is treated as Confidential or Restricted by default and only handled on managed endpoints.
Secure destruction
Cloud storage is securely erased via provider cryptographic erase (NIST SP 800-88 aligned, via AWS). Retired laptops are wiped to NIST SP 800-88 Purge level before resale or certified recycling.
Visitor control
Fractional Founders operates remote-first with no physical office processing customer data, so visitor control at our own premises is not applicable. Visitor controls at sub-processor data centres are covered by their published SOC 2 / ISO 27001 reports.
Endpoint controls
Full-disk encryption (FileVault / BitLocker), automatic OS updates, screen-lock, strong passcodes and reputable endpoint protection are required on every device. Production data is never stored locally.
Information security training & awareness
Our people are the first line of defence. Everyone working with customer data completes training and accepts the policies that govern how it must be handled.
Induction
Every joiner receives a security and data-protection briefing covering UK GDPR basics, phishing, password hygiene, device security and incident reporting before being granted access.
Annual refresher
Policies and the current threat landscape are reviewed with all personnel at least annually, with ad-hoc updates when significant risks emerge.
Phishing awareness
Personnel are trained to recognise and report suspicious messages. A clear internal reporting channel is published and reviewed.
Policy acknowledgement
Written acceptance of our Acceptable Use, Information Security and Data Protection policies is required from all staff and contractors.
Contractual obligations
Confidentiality and data-protection clauses appear in every staff, contractor and expert agreement. Obligations flow down to sub-processors via Data Processing Agreements.
Personnel security & vetting
We verify the people who deliver our services and tightly control their access to customer data across the joiner, mover and leaver lifecycle.
Identity & right to work
Identity and right-to-work are verified for all staff and contractors before any access to systems or customer data is granted.
Reference checks
Experts joining our network complete a structured two-referee workflow. Staff hires complete standard professional reference checks.
Confidentiality & IP clauses
Robust confidentiality and intellectual property clauses are included in every staff and expert agreement and survive termination.
Joiners, movers & leavers
Least-privilege access is provisioned on joining, reviewed on role change, and fully revoked on leaving — including portal account deletion via our existing cascading-delete flow.
Enhanced checks where required
DBS or equivalent disclosure checks are obtained where a specific engagement requires them (for example, work involving children, vulnerable adults or regulated sectors). They are not applied by default, as most engagements do not require them.
Sub-processors
We use a small set of carefully selected providers to deliver our service. Each one is bound by a Data Processing Agreement and only receives the minimum data necessary to perform its function.
| Provider | Purpose | Region | Compliance |
|---|---|---|---|
| Lovable Cloud (Supabase / AWS) | Database, authentication, object storage, edge functions | EU / UK | SOC 2, ISO 27001 (via AWS) |
| Resend | Transactional email delivery | EU / US | GDPR, DPA in place |
| Calendly | Strategy Session scheduling | US (SCCs) | GDPR, DPA in place |
| Cloudflare | CDN, DDoS protection, edge delivery | Global | SOC 2, ISO 27001 |
Your data rights
Under UK GDPR you have the right to access, rectify, erase, restrict, port, or object to the processing of your personal data. Contact us at any time to exercise these rights.
Report a security issue
If you believe you have found a security vulnerability, please disclose it responsibly by emailing us. We will acknowledge within 2 business days.
hello@fractionalfounders.co.ukNeed our full Technical & Organisational Measures document for a vendor assessment?
Request TOMs documentLast reviewed: July 2026