Trust & Security

How we protect your company data

This page is maintained by the FounderOS team to answer common security and privacy questions about the product. It describes the controls that are active in the application today. It is editable product content, not an independent certification or audit.

Invite-only access

FounderOS is not open to public sign-up. Accounts are created by administrators, and every member authenticates before reaching any company data.

Per-account data isolation

Row-level security is enforced on the database. Each member can only read and write their own records — finances, integrations, and profile data are scoped to the signed-in user.

Encrypted in transit

All traffic between your browser and FounderOS is served over HTTPS/TLS. Credentials and tokens are never sent over unencrypted connections.

Secure integration tokens

Tokens for connected tools (such as ClickUp) are exchanged server-side and stored against your account only. They are never exposed to other members or to unauthenticated visitors.

Shared responsibility

FounderOS provides the platform-level protections described above. Keeping your own account secure — using a strong, unique password and only connecting integrations you trust — remains your responsibility. We never display another member's data to you, and your data is never shown to other members.

Reporting a security concern

Found something that looks wrong? Contact your FounderOS administrator and we'll investigate promptly.