
Enterprise-grade security for your most sensitive financial data
Built on a zero-trust architecture, independently audited, and hosted on Microsoft Azure — so your data is protected at every layer of the stack.
Certifications & Compliance Standards
Our security posture is verified by independent auditors against the most rigorous standards in the industry.
SOC 2 Type II
Our SOC 2 Type II report demonstrates sustained operational excellence across all five trust service criteria — security, availability, processing integrity, confidentiality, and privacy — over a 12-month audit period. Available under NDA.
GDPR Compliant
We process personal data lawfully, transparently, and for specified purposes under the GDPR and UK GDPR. Our Data Processing Agreement (DPA) is available for all customers. Standard Contractual Clauses are used for all international data transfers.
ISO 27001 Aligned
Our information security management practices align with ISO/IEC 27001. Our infrastructure runs on Microsoft Azure, which holds direct ISO 27001, ISO 27017, and ISO 27018 certifications, extending verified assurance to our cloud environment.
CCPA / CPRA
California residents have full rights to access, delete, and opt out of any sharing of personal information. We honour Global Privacy Control (GPC) signals. We do not sell personal information. Our privacy practices are detailed in our Privacy Policy.
Azure Compliance
All data is hosted on Microsoft Azure (North Europe). Azure's infrastructure is certified under CIS Benchmarks, NIST CSF, FedRAMP High, and HIPAA. This provides an independently verified compliance baseline for our entire hosting environment.
CSA STAR Level 1
ForezynPlan has completed a Cloud Security Alliance (CSA) STAR Level 1 self-assessment against the Cloud Controls Matrix (CCM), and our disclosure is publicly available in the CSA STAR Registry for independent review.
Security architecture overview
Multiple independent layers of protection, so no single point of failure can compromise your data.
Data Encryption
AES-256 at rest · TLS 1.3 in transit
Every piece of data you store in ForezynPlan is encrypted before it ever touches a disk. Encryption keys are unique per customer tenant and rotated automatically on a 90-day cycle via Azure Key Vault with Hardware Security Module (HSM) backing.
- AES-256-GCM encryption for all data at rest
- TLS 1.3 enforced for all data in transit
- Per-tenant encryption keys — no shared key material
- Automated key rotation via Azure Key Vault (HSM-backed)
- Field-level encryption for all PII data elements
- Encrypted backups stored independently of primary data
Infrastructure Security
Microsoft Azure · North Europe
ForezynPlan's entire infrastructure runs on Microsoft Azure in the North Europe region. Our architecture is built on a zero-trust model — no service or component trusts another by default, and every connection requires explicit authentication and authorisation.
- Isolated Virtual Networks (VNets) per environment
- Azure DDoS Protection Standard — always on
- Azure Web Application Firewall (WAF) with OWASP ruleset
- Private endpoints only — databases are never publicly exposed
- Geo-redundant storage with multi-region failover
- Critical CVE patches deployed within 24 hours
Access & Identity
Zero-trust · MFA · RBAC · SSO
Access to ForezynPlan is governed by a zero-trust model. Every user — including ForezynPlan engineers — must authenticate through MFA and is granted only the minimum access required to perform their role.
- Multi-factor authentication (MFA) mandatory for all users
- Role-based access control (RBAC) with least-privilege enforcement
- SSO via SAML 2.0 and OAuth 2.0 / OIDC
- Privileged Identity Management (PIM) for just-in-time admin access
- Session timeout with device trust enforcement
- Quarterly access reviews for all internal personnel
Application security
Security is built into every line of code, not added as an afterthought.
Secure Development Lifecycle
OWASP · SAST · DAST
Security is integrated into every stage of our development process, not bolted on afterwards. All code changes are reviewed against OWASP Top 10 and our internal ASVS Level 2 baseline before they can reach production.
- OWASP Application Security Verification Standard (ASVS) Level 2 baseline
- Static Application Security Testing (SAST) on every pull request
- Dynamic Application Security Testing (DAST) in staging environments
- Mandatory peer code review with security gate before merge
- Security champions programme embedded within engineering teams
- Threat modelling for all new features handling financial data
Penetration Testing & Vulnerability Management
CREST-certified · Annual · CVSSv3
We take a proactive approach to finding vulnerabilities before attackers do. Every finding is triaged using CVSSv3 scoring, tracked to remediation, and verified via re-testing. Security researchers can also report issues through our responsible disclosure programme.
- Annual full-scope pentest by a CREST-accredited third party
- Quarterly internal vulnerability assessments
- CVSSv3 scoring — critical issues patched within 24 hours
- High-severity vulnerabilities remediated within 7 days
- Responsible disclosure programme (see section below)
- All findings tracked, verified, and documented for SOC 2 audit
Dependency & Supply Chain Security
SBOM · Snyk · Signed images
Modern applications are only as secure as their dependencies. We maintain a complete Software Bill of Materials (SBOM) and continuously monitor every third-party library and container image in our supply chain for known vulnerabilities.
- Software Bill of Materials (SBOM) maintained for all services
- Automated dependency scanning via Dependabot and Snyk
- Signed container images with provenance attestation
- All third-party libraries reviewed before introduction
- No unreviewed transitive dependencies in production
- Immutable container registry with image digest pinning
Operational security
Continuous monitoring, tamper-evident logging, and a battle-tested incident response programme.
24/7 Monitoring & Threat Detection
- SIEM platform with real-time alerting and correlation
- User and Entity Behaviour Analytics (UEBA) for anomaly detection
- Network intrusion detection and prevention (IDS/IPS)
- Microsoft Sentinel integration for cloud-native threat intelligence
- On-call security engineering rotation — 24 hours, 7 days a week
- Automated runbook execution for known threat signatures
Immutable Audit Logging
- Every user action, API call, and admin operation is logged
- Logs are tamper-evident and stored in a write-once archive
- 12-month retention by default; configurable for enterprise
- Searchable audit trail available to account administrators
- Streamed to SIEM for real-time correlation and analysis
- Audit export available in JSON and CSV formats
Incident Response
- Formal incident response plan with severity classification (P0–P3)
- P0 response SLA: 15 minutes to page; 1 hour to mitigate
- Dedicated incident commander role for P0/P1 events
- GDPR Article 33 breach notification to supervisory authority within 72 hours
- Affected users notified without undue delay where required
- Post-incident reviews with root-cause analysis and public status updates
Data residency & recovery
Data Residency
Choose where your data lives. All data remains within your chosen region and never crosses regional boundaries.
- EU (Azure North Europe — Netherlands) by default for EU/EEA customers
- US East region available for US-based customers
- Data never leaves your selected region without explicit consent
- GDPR-compliant EU residency guaranteed for European accounts
- Enterprise customers can request dedicated region configurations
Backup & Recovery
Automated, encrypted, geo-redundant backups keep your data safe from loss — with fast recovery guarantees.
- Automated daily backups with 30-day retention
- Point-in-time recovery (PITR) — restore to any second in the last 7 days
- Cross-region geo-redundant backup replication
- Disaster Recovery RTO < 4 hours; RPO < 1 hour
- Annual disaster recovery (DR) exercise with documented results
Employee & organisational security
Security is a company-wide responsibility, not just an engineering concern.
Background Screening
All employees and contractors who access production systems or customer data undergo background verification before their start date. Screening scope is proportionate to data access level.
Security Awareness Training
Mandatory annual security awareness training for all staff. Engineers complete additional role-specific secure coding training. Quarterly phishing simulation exercises are run across the organisation.
Access Governance
Strict joiners-movers-leavers process. All system access is provisioned on the day of joining and fully revoked on the day of departure. Access reviews are conducted quarterly for all personnel with elevated privileges.
Device Security
All ForezynPlan-issued devices are enrolled in Mobile Device Management (MDM), with full-disk encryption, screen lock, and remote-wipe capability enforced. Personal device access to production systems is prohibited.
Found a security issue?
We value the work of the security research community. If you discover a vulnerability in ForezynPlan, please report it responsibly and we will work with you to resolve it quickly.
Safe Harbour
No legal action for good-faith research
48 h Response
Acknowledgement within 2 business days
GDPR Process
Privacy-first coordinated disclosure
PGP key available on request · All reports treated in strict confidence
Email security@forezynplan.com with a clear description of the issue, steps to reproduce, and your assessment of the potential impact.
We will acknowledge receipt of your report within 2 business days and assign an internal tracking reference number.
Our security team assesses the report, validates the vulnerability, and determines severity using CVSSv3 scoring.
We work to remediate confirmed vulnerabilities according to our SLAs. We will keep you updated on progress and notify you when the fix is deployed.
In scope: ForezynPlan web app, API endpoints, authentication flows, and data handling. Out of scope: Social engineering, physical attacks, and third-party services. We follow coordinated disclosure and credit researchers with their permission.
Need a higher security tier?
Enterprise customers receive dedicated security reviews, custom SLAs, BAA agreements for healthcare data, and a named security contact — everything you need to satisfy your internal procurement and compliance requirements.
- Custom SLA up to 99.99% guaranteed availability
- Dedicated security architecture review and walkthrough
- SOC 2 Type II report available under NDA
- Business Associate Agreement (BAA) for HIPAA-covered entities
- Custom data residency and retention policies
- Named security contact with priority escalation path
- Custom SSO / SAML 2.0 configuration and testing
- Quarterly security briefings with your security team
- Penetration test results available under NDA
- Dedicated vulnerability disclosure SLA
Request a security review
Our security team will walk you through our architecture, controls, and compliance posture — and share our SOC 2 Type II report and penetration test summary under NDA.
