TechVentures hit 96% accuracy on Q1 forecast
GlobalRetail generated 12 scenarios in 8 min
ScaleUp reduced forecast cycle from 2wk to 3hr
NexGen found $4.2M in budget optimization
Security & Compliance

Enterprise-grade security for your most sensitive financial data

Built on a zero-trust architecture, independently audited, and hosted on Microsoft Azure — so your data is protected at every layer of the stack.

99.95%
Uptime SLA
Guaranteed availability
AES-256
Encryption standard
At rest and in transit
Annual
Penetration testing
By CREST-accredited third parties
< 72 h
Breach notification
GDPR Article 33 compliance
Independently Verified

Certifications & Compliance Standards

Our security posture is verified by independent auditors against the most rigorous standards in the industry.

Report available under NDA

SOC 2 Type II

Our SOC 2 Type II report demonstrates sustained operational excellence across all five trust service criteria — security, availability, processing integrity, confidentiality, and privacy — over a 12-month audit period. Available under NDA.

DPA available

GDPR Compliant

We process personal data lawfully, transparently, and for specified purposes under the GDPR and UK GDPR. Our Data Processing Agreement (DPA) is available for all customers. Standard Contractual Clauses are used for all international data transfers.

Azure certified

ISO 27001 Aligned

Our information security management practices align with ISO/IEC 27001. Our infrastructure runs on Microsoft Azure, which holds direct ISO 27001, ISO 27017, and ISO 27018 certifications, extending verified assurance to our cloud environment.

No data sales

CCPA / CPRA

California residents have full rights to access, delete, and opt out of any sharing of personal information. We honour Global Privacy Control (GPC) signals. We do not sell personal information. Our privacy practices are detailed in our Privacy Policy.

HIPAA-eligible

Azure Compliance

All data is hosted on Microsoft Azure (North Europe). Azure's infrastructure is certified under CIS Benchmarks, NIST CSF, FedRAMP High, and HIPAA. This provides an independently verified compliance baseline for our entire hosting environment.

Publicly registered

CSA STAR Level 1

ForezynPlan has completed a Cloud Security Alliance (CSA) STAR Level 1 self-assessment against the Cloud Controls Matrix (CCM), and our disclosure is publicly available in the CSA STAR Registry for independent review.

Defence in Depth

Security architecture overview

Multiple independent layers of protection, so no single point of failure can compromise your data.

Data Encryption

AES-256 at rest · TLS 1.3 in transit

Every piece of data you store in ForezynPlan is encrypted before it ever touches a disk. Encryption keys are unique per customer tenant and rotated automatically on a 90-day cycle via Azure Key Vault with Hardware Security Module (HSM) backing.

  • AES-256-GCM encryption for all data at rest
  • TLS 1.3 enforced for all data in transit
  • Per-tenant encryption keys — no shared key material
  • Automated key rotation via Azure Key Vault (HSM-backed)
  • Field-level encryption for all PII data elements
  • Encrypted backups stored independently of primary data

Infrastructure Security

Microsoft Azure · North Europe

ForezynPlan's entire infrastructure runs on Microsoft Azure in the North Europe region. Our architecture is built on a zero-trust model — no service or component trusts another by default, and every connection requires explicit authentication and authorisation.

  • Isolated Virtual Networks (VNets) per environment
  • Azure DDoS Protection Standard — always on
  • Azure Web Application Firewall (WAF) with OWASP ruleset
  • Private endpoints only — databases are never publicly exposed
  • Geo-redundant storage with multi-region failover
  • Critical CVE patches deployed within 24 hours

Access & Identity

Zero-trust · MFA · RBAC · SSO

Access to ForezynPlan is governed by a zero-trust model. Every user — including ForezynPlan engineers — must authenticate through MFA and is granted only the minimum access required to perform their role.

  • Multi-factor authentication (MFA) mandatory for all users
  • Role-based access control (RBAC) with least-privilege enforcement
  • SSO via SAML 2.0 and OAuth 2.0 / OIDC
  • Privileged Identity Management (PIM) for just-in-time admin access
  • Session timeout with device trust enforcement
  • Quarterly access reviews for all internal personnel
Secure by Design

Application security

Security is built into every line of code, not added as an afterthought.

Secure Development Lifecycle

OWASP · SAST · DAST

Security is integrated into every stage of our development process, not bolted on afterwards. All code changes are reviewed against OWASP Top 10 and our internal ASVS Level 2 baseline before they can reach production.

  • OWASP Application Security Verification Standard (ASVS) Level 2 baseline
  • Static Application Security Testing (SAST) on every pull request
  • Dynamic Application Security Testing (DAST) in staging environments
  • Mandatory peer code review with security gate before merge
  • Security champions programme embedded within engineering teams
  • Threat modelling for all new features handling financial data

Penetration Testing & Vulnerability Management

CREST-certified · Annual · CVSSv3

We take a proactive approach to finding vulnerabilities before attackers do. Every finding is triaged using CVSSv3 scoring, tracked to remediation, and verified via re-testing. Security researchers can also report issues through our responsible disclosure programme.

  • Annual full-scope pentest by a CREST-accredited third party
  • Quarterly internal vulnerability assessments
  • CVSSv3 scoring — critical issues patched within 24 hours
  • High-severity vulnerabilities remediated within 7 days
  • Responsible disclosure programme (see section below)
  • All findings tracked, verified, and documented for SOC 2 audit

Dependency & Supply Chain Security

SBOM · Snyk · Signed images

Modern applications are only as secure as their dependencies. We maintain a complete Software Bill of Materials (SBOM) and continuously monitor every third-party library and container image in our supply chain for known vulnerabilities.

  • Software Bill of Materials (SBOM) maintained for all services
  • Automated dependency scanning via Dependabot and Snyk
  • Signed container images with provenance attestation
  • All third-party libraries reviewed before introduction
  • No unreviewed transitive dependencies in production
  • Immutable container registry with image digest pinning
Always On

Operational security

Continuous monitoring, tamper-evident logging, and a battle-tested incident response programme.

24/7 Monitoring & Threat Detection

  • SIEM platform with real-time alerting and correlation
  • User and Entity Behaviour Analytics (UEBA) for anomaly detection
  • Network intrusion detection and prevention (IDS/IPS)
  • Microsoft Sentinel integration for cloud-native threat intelligence
  • On-call security engineering rotation — 24 hours, 7 days a week
  • Automated runbook execution for known threat signatures

Immutable Audit Logging

  • Every user action, API call, and admin operation is logged
  • Logs are tamper-evident and stored in a write-once archive
  • 12-month retention by default; configurable for enterprise
  • Searchable audit trail available to account administrators
  • Streamed to SIEM for real-time correlation and analysis
  • Audit export available in JSON and CSV formats

Incident Response

  • Formal incident response plan with severity classification (P0–P3)
  • P0 response SLA: 15 minutes to page; 1 hour to mitigate
  • Dedicated incident commander role for P0/P1 events
  • GDPR Article 33 breach notification to supervisory authority within 72 hours
  • Affected users notified without undue delay where required
  • Post-incident reviews with root-cause analysis and public status updates
Your Data, Your Control

Data residency & recovery

Data Residency

Choose where your data lives. All data remains within your chosen region and never crosses regional boundaries.

  • EU (Azure North Europe — Netherlands) by default for EU/EEA customers
  • US East region available for US-based customers
  • Data never leaves your selected region without explicit consent
  • GDPR-compliant EU residency guaranteed for European accounts
  • Enterprise customers can request dedicated region configurations

Backup & Recovery

Automated, encrypted, geo-redundant backups keep your data safe from loss — with fast recovery guarantees.

  • Automated daily backups with 30-day retention
  • Point-in-time recovery (PITR) — restore to any second in the last 7 days
  • Cross-region geo-redundant backup replication
  • Disaster Recovery RTO < 4 hours; RPO < 1 hour
  • Annual disaster recovery (DR) exercise with documented results
People & Process

Employee & organisational security

Security is a company-wide responsibility, not just an engineering concern.

Background Screening

All employees and contractors who access production systems or customer data undergo background verification before their start date. Screening scope is proportionate to data access level.

Security Awareness Training

Mandatory annual security awareness training for all staff. Engineers complete additional role-specific secure coding training. Quarterly phishing simulation exercises are run across the organisation.

Access Governance

Strict joiners-movers-leavers process. All system access is provisioned on the day of joining and fully revoked on the day of departure. Access reviews are conducted quarterly for all personnel with elevated privileges.

Device Security

All ForezynPlan-issued devices are enrolled in Mobile Device Management (MDM), with full-disk encryption, screen lock, and remote-wipe capability enforced. Personal device access to production systems is prohibited.

Responsible Disclosure

Found a security issue?

We value the work of the security research community. If you discover a vulnerability in ForezynPlan, please report it responsibly and we will work with you to resolve it quickly.

Safe Harbour

No legal action for good-faith research

48 h Response

Acknowledgement within 2 business days

GDPR Process

Privacy-first coordinated disclosure

security@forezynplan.com

PGP key available on request · All reports treated in strict confidence

01Submit

Email security@forezynplan.com with a clear description of the issue, steps to reproduce, and your assessment of the potential impact.

02Acknowledge

We will acknowledge receipt of your report within 2 business days and assign an internal tracking reference number.

03Investigate

Our security team assesses the report, validates the vulnerability, and determines severity using CVSSv3 scoring.

04Remediate

We work to remediate confirmed vulnerabilities according to our SLAs. We will keep you updated on progress and notify you when the fix is deployed.

In scope: ForezynPlan web app, API endpoints, authentication flows, and data handling. Out of scope: Social engineering, physical attacks, and third-party services. We follow coordinated disclosure and credit researchers with their permission.

Enterprise

Need a higher security tier?

Enterprise customers receive dedicated security reviews, custom SLAs, BAA agreements for healthcare data, and a named security contact — everything you need to satisfy your internal procurement and compliance requirements.

  • Custom SLA up to 99.99% guaranteed availability
  • Dedicated security architecture review and walkthrough
  • SOC 2 Type II report available under NDA
  • Business Associate Agreement (BAA) for HIPAA-covered entities
  • Custom data residency and retention policies
  • Named security contact with priority escalation path
  • Custom SSO / SAML 2.0 configuration and testing
  • Quarterly security briefings with your security team
  • Penetration test results available under NDA
  • Dedicated vulnerability disclosure SLA

Request a security review

Our security team will walk you through our architecture, controls, and compliance posture — and share our SOC 2 Type II report and penetration test summary under NDA.

Security teamsecurity@forezynplan.com
Response SLAWithin 1 business day
Get Started Today

Security you can trust
from day one

Start a free 7-day trial with enterprise-grade security built in. No credit card required.

No credit card required
7-day free trial
Cancel anytime
Security & Compliance — ForezynPlan — ForezynPlan