Security
Last updated:
FoxtINN is built for operators in hospitality and related service businesses. Security is owned end-to-end by our team. The practices below describe how we run production today. Formal audit reports, when they exist, are shared under NDA. We do not display SOC 2, ISO, or HIPAA certification badges on this site.
SOC 2 program
FoxtINN maintains a SOC 2 Type II program covering Security, Availability, and Confidentiality. The program is in progress. When a report is available it is shared under NDA — it is not a public badge and we do not claim completed certification on this site. Request status or materials from hello@foxtcon.com or Call Laila at (816) 816-3823.
Encryption
TLS 1.3 in transit. AES-256 at rest across RDS, S3, and Redis for production data stores we operate. Customer-managed keys (CMK) are available on Portfolio where contracted.
Network isolation
Production runs on AWS in us-east-2 by default. Databases sit in private subnets with no public IP. Backend services run on ECS Fargate with VPC-only egress except for required integrations.
Identity & access
Role-based access control with optional approval flows on sensitive actions. SSO via SAML 2.0 / OIDC and SCIM 2.0 provisioning are on the Portfolio roadmap and are not generally available today unless an order form says otherwise.
Logging & monitoring
Admin actions are captured in an audit log. We monitor authentication anomalies and alert on security-relevant events. Retention of audit logs is described in the Data Retention Schedule.
Penetration testing
External pentest is performed periodically. Findings are tracked and remediated under our internal SLA. Summaries are available to enterprise customers under NDA. We do not publish raw reports or invent ISO certificate numbers.
Vendor security
Subprocessors are reviewed periodically. Tier-1 vendors are expected to maintain SOC 2 attestation or an equivalent control report. See the Subprocessors page for the current list.
Incident response
If we confirm a security incident affecting Customer Data, we notify affected customers as required by the DPA, BAA, and applicable law. Report suspected incidents to hello@foxtcon.com or support@foxtcon.com.
Customer responsibilities
You are responsible for user provisioning, endpoint security, and not introducing PHI until a BAA is signed and the workspace is configured. Do not share portal credentials.
Questions? Call Laila at (816) 816-3823 · hello@foxtcon.com · Back to Trust Center