Skip to content
FOXAF
Security & Trust

Your customers' data, isolated by design.

FOXAF is built multi-workspace from the ground up. Each WhatsApp connection runs in its own isolated environment, AI agents can use your own keys, and no data ever leaks between workspaces. No shared models, no hidden flows.

The four pillars

Isolation, not just 'we encrypt things'

Most B2B SaaS leaks happen at the tenant-scoping layer. FOXAF was architected with that as the starting point.

Tenant isolation

Every business record is scoped to your workspace and enforced at the data layer — not just the UI. Cross-workspace access is blocked by design, closing the most common B2B SaaS leak vector before it can happen.

WhatsApp session isolation

Every WhatsApp connection runs in its own isolated environment. One workspace's session issue can never touch another. Per-workspace send-rate throttling keeps every connection in good standing.

AI provider isolation

Bring your own AI keys when you want — your conversations never train any shared model. Per-agent knowledge bases stay scoped to your workspace with strict access checks on every retrieval.

Audit-first

Every meaningful action (login, contact edit, campaign send, channel connect, AI hand-off) is written to an immutable activity log with actor, IP, timestamp, before/after diff.

Architecture

Where your data lives, in one picture

The shape of FOXAF's data plane. Every node enforces tenant scoping at write time.

Inside one workspace
Contacts · pipelines · campaigns
Isolated WhatsApp connection
AI agent + private knowledge base
Audit log (every action)
Strict workspace scoping enforced on every read and every write. No back-door access paths.
External services
WhatsApp
Tokens encrypted at rest, signed webhooks
Email · SMS · Payment providers
Cryptographic signatures verified on every callback
AI model providers (BYO keys)
Your keys, your usage — never shared
Dedicated server · encrypted backups
Off-site daily backups, region options available
Controls

What's in place today

Every item below is live in the product — not on a roadmap, not a 'coming soon'.

Multi-factor authentication (2FA)

Every user can turn on TOTP (Google Authenticator / Authy) or email OTP. On Pro and Enterprise, admins can enforce 2FA across the whole workspace so no one logs in with a password alone.

Application-layer secret encryption

On top of encryption at rest and TLS in transit, secrets like API keys and WhatsApp tokens are encrypted again at the application layer before they ever touch the database.

TLS everywhere

HTTPS-only across the entire site. Custom domains you connect get auto-issued SSL certificates so your customer-facing pages stay secure end-to-end.

Role-based access

Owner, Admin, Agent and Viewer roles — every action is gated by a permission check. Team invitations use signed, expiring tokens.

Per-user module permissions

Go beyond roles: restrict an individual user to the exact modules they need. Limit someone to the Inbox without ever exposing Campaigns, Pipelines or Lead Finder.

Audited support access

FOXAF support can only reach your workspace through an impersonation mechanism — and every impersonation is recorded in your own activity log, actor and timestamp included.

Signed webhooks

Outbound webhooks are cryptographically signed so your endpoints can verify the payload came from FOXAF. Inbound webhooks are verified before any data is written.

Suppression honoured

Workspace-scoped Do Not Contact lists for both email and phone. Unsubscribe links are signed; double-confirm prevents accidental opt-outs by email scanners.

Daily encrypted backups

Every workspace is backed up daily to encrypted off-site storage. Region options available for teams with data-residency requirements.

Standards

Standards we follow today

  • GDPR-aligned data handling (DSAR + right-to-erasure)
  • OWASP Top 10 — assessed in build review
  • Meta Business API ToS — required for Cloud channels
  • Twilio messaging policy compliance
  • Resend / Mailgun sending best practices (SPF · DKIM · DMARC)
Honest disclosure

What we have not (yet) certified

SOC 2 Type II

Built to the SOC 2 control set today, with a formal Type II audit on the roadmap. Enterprise customers can request our current security questionnaire on request.

ISO 27001

Same path — controls are in place, formal cert pending.

HIPAA

Out of scope. FOXAF is not intended for PHI today.

FAQ

Data, privacy, exit

Where is my data stored and who can see it?+

Your data is isolated per workspace (multi-tenant separation) and never shared between customers. FOXAF support can only access a workspace through an audited impersonation mechanism, recorded in your activity log.

Is my data encrypted?+

Yes — encrypted in transit (TLS) and at rest, with sensitive secrets like API keys and WhatsApp tokens encrypted again at the application layer.

Does FOXAF support two-factor authentication?+

Yes — every user can enable TOTP (Google Authenticator / Authy) or email OTP, and Pro and Enterprise admins can enforce 2FA across the whole workspace.

Can I control what each team member can access?+

Yes — Owner, Admin, Agent and Viewer roles, plus per-user module permissions, so you can limit someone to the Inbox without exposing Campaigns, Pipelines or Lead Finder.

How are WhatsApp QR sessions isolated?+

Each workspace's WhatsApp QR session runs in its own isolated process, so one workspace can never reach another's WhatsApp connection.

Can I use my own AI keys?+

Yes — bring your own Claude or GPT keys (encrypted and private to your workspace) so prompts and usage run under your own provider account.

Is FOXAF SOC 2 or ISO certified?+

A formal SOC 2 Type II audit is on our roadmap; the platform is already built to that control set today. Enterprise customers can request our current security questionnaire.

How do I report a security issue?+

Email info@foxaf.com and we will route it straight to our security team — we aim to acknowledge within 48 hours.

Can I export my data?+

Yes — every entity (contacts, conversations, campaigns, deals) exports to CSV from the workspace UI. The full public API is documented at /docs.

What happens if I cancel?+

Your data stays available for 30 days post-cancellation for re-export. After that it is permanently deleted from primary storage; backups age out within 35 days.

Do you support GDPR / DSAR?+

Yes. Subject Access Requests and right-to-erasure are handled through the workspace admin. Audit log proves the action was performed.

Need our security questionnaire?

Enterprise customers can request our current security questionnaire and sub-processor list. Talk to sales and we will turn it round in 48 hours.