Security
Last updated:
FoxtINN is built for operators in regulated industries · hospitality, healthcare-adjacent clinics, retail. Security is owned end-to-end by our team and embedded in product surfaces. Claims below describe current practices; formal audit reports are shared under NDA.
SOC 2 program
FoxtINN maintains a SOC 2 Type II program covering Security, Availability, and Confidentiality. The program is in progress; when a report is available it is shared under NDA. Contact hello@foxtcon.com to request status or materials. We do not claim completed certification on this site until a report is issued.
Encryption
TLS 1.3 in transit. AES-256 at rest across RDS, S3, and Redis. Customer-managed keys (CMK) available on Portfolio.
Network isolation
Production runs on AWS in us-east-2. Database in private subnets, no public IP. Backend in ECS Fargate with VPC-only egress.
Identity & access
Role-based access control with optional approval flows on sensitive actions. SSO via SAML 2.0 / OIDC and SCIM 2.0 provisioning are on the Portfolio roadmap and are not generally available today.
Logging & monitoring
Admin actions are captured in an audit log. Anomaly detection on auth events. Alerting on security-relevant events.
Penetration testing
External pentest performed periodically. Findings are tracked and remediated under our internal SLA. Summaries available to enterprise customers under NDA.
Vendor security
Subprocessors are reviewed periodically. Tier-1 vendors are expected to maintain SOC 2 attestation or an equivalent control report.
Questions? Call Laila at (816) 816-3823 · hello@foxtcon.com · Back to Trust Center