Security & privacy

The shortest version: there is nowhere for your data to go.

Most security pages are a list of things a vendor will do for you. This one is mostly a list of things the software cannot do at all, because there are no servers for it to connect to.

The short answer

No account

There is no sign-up, no email address held by us, no password reset server, and no vendor-side copy of your user list. The first account you create exists on your disk and nowhere else.

A file, not a service

Your records are in a SQLite database in the data/ folder. Read it with any SQLite tool, copy it, back it up, delete it. And because a portable file beats an argument, Settings exports every record type to CSV — one button each, no account required, nothing gated behind a subscription.

Five, and all five are written down

The Privacy Notice names every outbound connection the software can ever make: the model endpoint you configure (a process on your own machine unless you change it), the public web pages you ask it to research — including the team and leadership pages it follows to find the people who work there — DuckDuckGo when you run a company search, Companies House when you supply your own key for UK filings, and the first-run fetch of a model file whose address the manifest publishes. That is the whole list. There is no update check, no licence call, no crash report and no usage ping.

What the software is built to refuse

These are not policies. A policy is a promise; a refusal is a behaviour that does not change when someone is in a hurry, or when a customer asks nicely.

  • The model cannot post to the ledger. Anything it proposes goes through the same double-entry, permission and period controls a human's entry does. An entry that does not balance is refused by the engine, and the refusal is not overridable by the model.
  • The model cannot overwrite a correction you made. Once a field's origin is recorded as yours, no crawler, import or model can replace it — at any confidence.
  • The model cannot overwrite a value with an empty one. A low-confidence proposal cannot replace a high-confidence stored value either.
  • Content from a web page cannot issue instructions. Retrieved pages are treated as data and never as authority, and every request is checked against private address space on every redirect hop, so a lookup cannot be steered at your network.
  • Posted entries are immutable. A mistake is corrected with a reversing entry and a new one. The history of what you believed, and when, survives.
  • Money is never a floating-point number. Amounts are stored as integer minor units, so totals do not drift.
  • One workspace cannot read another's records by changing an identifier. The workspace is read from your session, never from a URL or a request body.
  • A new route cannot forget to check the CSRF token. The check happens inside the authentication dependency, so forgetting to add it is not a thing that can happen.

When it leaves the machine, it becomes harder

On one machine, FoundrySuite serves 127.0.0.1 over plain HTTP, and that is correct: there is no wire for anyone to intercept.

The moment you bind it to a network interface so staff can reach it, HTTPS becomes mandatory. The session cookie is marked Secure, plaintext requests are redirected in a way that keeps your session intact, HSTS is sent — and if none of that is configured, the application refuses to start and tells you why.

There is an override, because some sites genuinely cannot get a certificate. It prints a warning on every single launch. The insecure state is reachable on purpose and never by accident.

The API surface is closed to the anonymous

  • The API documentation endpoints require a signed-in session.
  • Filesystem paths in the system configuration are returned to owners only.
  • Signing in is throttled per address and per account, so one person's typo cannot lock out the office.
  • Further registrations on a machine need an invitation code, checked before the account is written — a refused attempt leaves nothing behind and cannot be used to discover who has an account.

Check the claims rather than believing them

You should not have to take a vendor's word for any of this. Four ways not to.

Inspect the network

Open the developer tools and watch. With no research feature in use, FoundrySuite makes no external requests at all — not for fonts, not for telemetry, and not for the licence check, which reads a local file and verifies a signature against a key inside the program. Every byte stays on 127.0.0.1.

Check the download's fingerprint

Every release publishes a SHA-256 checksum, and the same digest appears in your receipt email. Run one command, compare, and you know the file on your disk is the file we built. The exact command is on the download page — and it is worth being clear that this proves the file was not altered in transit, not who sent it, which is why you check it against the email rather than the website.

Open the database

Shut the app down and open the SQLite file in any reader. There is no second copy anywhere else, because there is no second machine.

Run the tests

The suite that ships alongside the source is 1714 tests against a real migrated database and the real services — no mocks, no fake model responses. A test that passes because it agreed with a stub is worse than no test at all.

Written down before you ask

Inside the download you will find an end user licence, a privacy notice, an AI facts sheet written for a compliance officer rather than a lawyer, and a compliance document that includes an honest list of what is still missing. We would rather you read the gaps before you buy than discover them during a procurement review. Every one of them is described on the legal page, including the two facts we have not been given yet →

The questions we would ask you to ask us

Steal them. They are the ones that have caught other vendors out.

Where is my data physically stored?

In a SQLite file in the data/ folder inside the FoundrySuite directory, on the drive you installed it to. If you want it on a specific drive, install it there.

Does anything leave my machine automatically?

No. The Privacy Notice lists every outbound connection the Software can make, and all three are ones you asked for: the model endpoint you configure — a process on your own machine at 127.0.0.1 unless you point it elsewhere — the websites you ask it to research, and a first-run fetch of a model file whose address the manifest publishes, which is cancelled if you do not want it. There is no update check, no licence call, no crash report and no usage ping. The licence check is a local file read: it works identically on a machine that has never been online.

Does my licence ever expire?

No, and this is enforced rather than promised. A purchased licence is a document we signed, and FoundrySuite rejects any licence carrying an expiry date — all five spellings of it — rather than honouring one. The instalment plans on the pricing page are ways of paying for that same permanent licence, not rentals.

The one thing that does carry an end date is the thirty-day trial, which is a different kind of document precisely because nobody has paid for it. When a trial ends the software stops starting and nothing else changes; your data is untouched, and there is no remote switch that could have told us it was still running.

Can your staff or anyone else read my data?

We hold no copy, so we cannot. Whoever has filesystem access to the machine or the folder has the data — which is the same exposure as any local application, and the reason the deployment guide spends as much on disk permissions as it does on HTTPS.

What happens to my data if I stop paying?

It stays where it is, in a format you can read without us. A licence that expires does not turn into an unreadable database.

Do you train anything on my data?

There is no data to train on, because nothing reaches us. If you configure a remote model endpoint, that question becomes a question for that endpoint's operator, and FoundrySuite will tell you when you are sending to one.

Compliance documents

They ship inside the download, as files you can hand to someone who asks for them rather than as a page you have to keep asking us for.

Data processing

What we process, where it is stored, how long we keep it, and what we do not do with it. Short, because the honest answer is short: we hold no copy of anything, because nothing reaches us.

Sub-processors

There are none for your business data. The only component with any external dependency is the local language model, which runs on your own hardware, and the optional remote inference endpoint you would have to configure yourself.

Licence terms

Per workstation, perpetual, no renewal. What a workstation is, what you may not do, and what happens to your data if you stop paying.

Security overview

How the application is built to behave: the transport it uses, how sessions are stored, how tenant isolation is enforced, and the AI disclosure record for every model call it makes.

Every one of these is a document you read, not a page you have to trust. If a customer's compliance officer asks, the answer is a file in a folder you already have — the legal page lists all four and says which facts are still missing.