Your customers' data, isolated by design.
FOXAF is built multi-workspace from the ground up. Each WhatsApp connection runs in its own isolated environment, AI agents can use your own keys, and no data ever leaks between workspaces. No shared models, no hidden flows.
Isolation, not just 'we encrypt things'
Most B2B SaaS leaks happen at the tenant-scoping layer. FOXAF was architected with that as the starting point.
Tenant isolation
Every business record is scoped to your workspace and enforced at the data layer — not just the UI. Cross-workspace access is blocked by design, closing the most common B2B SaaS leak vector before it can happen.
WhatsApp session isolation
Every WhatsApp connection runs in its own isolated environment. One workspace's session issue can never touch another. Per-workspace send-rate throttling keeps every connection in good standing.
AI provider isolation
Bring your own AI keys when you want — your conversations never train any shared model. Per-agent knowledge bases stay scoped to your workspace with strict access checks on every retrieval.
Audit-first
Every meaningful action (login, contact edit, campaign send, channel connect, AI hand-off) is written to an immutable activity log with actor, IP, timestamp, before/after diff.
Where your data lives, in one picture
The shape of FOXAF's data plane. Every node enforces tenant scoping at write time.
What's in place today
Every item below is live in the product — not on a roadmap, not a 'coming soon'.
Multi-factor authentication (2FA)
Every user can turn on TOTP (Google Authenticator / Authy) or email OTP. On Pro and Enterprise, admins can enforce 2FA across the whole workspace so no one logs in with a password alone.
Application-layer secret encryption
On top of encryption at rest and TLS in transit, secrets like API keys and WhatsApp tokens are encrypted again at the application layer before they ever touch the database.
TLS everywhere
HTTPS-only across the entire site. Custom domains you connect get auto-issued SSL certificates so your customer-facing pages stay secure end-to-end.
Role-based access
Owner, Admin, Agent and Viewer roles — every action is gated by a permission check. Team invitations use signed, expiring tokens.
Per-user module permissions
Go beyond roles: restrict an individual user to the exact modules they need. Limit someone to the Inbox without ever exposing Campaigns, Pipelines or Lead Finder.
Audited support access
FOXAF support can only reach your workspace through an impersonation mechanism — and every impersonation is recorded in your own activity log, actor and timestamp included.
Signed webhooks
Outbound webhooks are cryptographically signed so your endpoints can verify the payload came from FOXAF. Inbound webhooks are verified before any data is written.
Suppression honoured
Workspace-scoped Do Not Contact lists for both email and phone. Unsubscribe links are signed; double-confirm prevents accidental opt-outs by email scanners.
Daily encrypted backups
Every workspace is backed up daily to encrypted off-site storage. Region options available for teams with data-residency requirements.
Standards we follow today
- GDPR-aligned data handling (DSAR + right-to-erasure)
- OWASP Top 10 — assessed in build review
- Meta Business API ToS — required for Cloud channels
- Twilio messaging policy compliance
- Resend / Mailgun sending best practices (SPF · DKIM · DMARC)
What we have not (yet) certified
Built to the SOC 2 control set today, with a formal Type II audit on the roadmap. Enterprise customers can request our current security questionnaire on request.
Same path — controls are in place, formal cert pending.
Out of scope. FOXAF is not intended for PHI today.
Data, privacy, exit
Where is my data stored and who can see it?+
Your data is isolated per workspace (multi-tenant separation) and never shared between customers. FOXAF support can only access a workspace through an audited impersonation mechanism, recorded in your activity log.
Is my data encrypted?+
Yes — encrypted in transit (TLS) and at rest, with sensitive secrets like API keys and WhatsApp tokens encrypted again at the application layer.
Does FOXAF support two-factor authentication?+
Yes — every user can enable TOTP (Google Authenticator / Authy) or email OTP, and Pro and Enterprise admins can enforce 2FA across the whole workspace.
Can I control what each team member can access?+
Yes — Owner, Admin, Agent and Viewer roles, plus per-user module permissions, so you can limit someone to the Inbox without exposing Campaigns, Pipelines or Lead Finder.
How are WhatsApp QR sessions isolated?+
Each workspace's WhatsApp QR session runs in its own isolated process, so one workspace can never reach another's WhatsApp connection.
Can I use my own AI keys?+
Yes — bring your own Claude or GPT keys (encrypted and private to your workspace) so prompts and usage run under your own provider account.
Is FOXAF SOC 2 or ISO certified?+
A formal SOC 2 Type II audit is on our roadmap; the platform is already built to that control set today. Enterprise customers can request our current security questionnaire.
How do I report a security issue?+
Email info@foxaf.com and we will route it straight to our security team — we aim to acknowledge within 48 hours.
Can I export my data?+
Yes — every entity (contacts, conversations, campaigns, deals) exports to CSV from the workspace UI. The full public API is documented at /docs.
What happens if I cancel?+
Your data stays available for 30 days post-cancellation for re-export. After that it is permanently deleted from primary storage; backups age out within 35 days.
Do you support GDPR / DSAR?+
Yes. Subject Access Requests and right-to-erasure are handled through the workspace admin. Audit log proves the action was performed.
Need our security questionnaire?
Enterprise customers can request our current security questionnaire and sub-processor list. Talk to sales and we will turn it round in 48 hours.