Trust & security
Every claim on this page, you can go check yourself.
How Folio protects your work and proves what’s yours: the database rules that enforce it, and the record you can check yourself at /verify. No jargon, no hand-waving.
Proof, not a promise
Folio’s Integrity Certificates aren’t a badge you take on faith. Each one is backed by a hash-chained record of the document’s real edit history, and anyone with the public /verify/[code] link can check it: an instructor, an editor, a reader. Today that check runs against Folio’s own record. The offline signature check and the independent timestamp anchor are built and switch on once signing is enabled on this deployment. How verification works, step by step.
Detection is being switched off — proof isn’t
A growing list of universities have disabled, discontinued, or never enabled AI-writing detection, because a probability score isn’t evidence anyone can act on. We keep a running list of who has stepped back, sourced to each institution’s own announcement — and what they use instead.
Attested, not just disclosed
Newer AI-disclosure features from other platforms, including Moodle's, added in version 4.5, flag content made with that platform's own built-in AI tool. They say nothing about work drafted anywhere else. Folio's Integrity Certificate doesn't care which tool you used: it's a hash-chained record of your actual writing and research process that anyone can check at /verify, not a label scoped to one vendor's own generator.
Access enforced at the database, not just the interface
Access is enforced in Postgres itself with row-level security, not only in the interface. Even a bug in the application can’t hand your data to someone else, because the database refuses to return it.
We don’t mine your work
Your content is yours. Folio’s AI answers from the sources you give it; we do not sell your data, and we do not train models on your writing.
Your data, your control
Export all your data in a machine-readable format, or permanently delete your account yourself, anytime, from Settings → Account — no support ticket required. If you delete, your personal data and content are gone within 30 days, except where compliance requires retention. Full detail in our privacy policy.
Screened before it reaches your bibliography
Folio flags retracted papers and expressions of concern before they reach your bibliography, so a withdrawn study never quietly props up your argument.
Compliance posture
Folio is built to a GDPR-aligned standard, and a Data Processing Agreement is available on request. If you’re evaluating Folio for a team or lab, your export, deletion, and access rights are the same ones covered above — see our privacy policy for the full detail, and the subprocessor register for every third party we send data to and why.
Have questions about how we handle your data?
Email us and we'll walk you through it — no sales pitch, just a straight answer.
Contact us