Trust & security

Institution data sheet

What your security review actually needs.

One page for the security reviewer, the DPO, and the procurement lead: who touches your data, how export and deletion work, what retention means in practice, and — just as plainly — what we don't have yet.

Last reviewed September 10, 2026 · English only, Hebrew in progress

Subprocessors

10 third parties process data on this deployment today, each gated on the feature it powers — a vendor listed here is one Folio is actually configured to use, not one it could theoretically use.

  • Supabase (Postgres + object storage)The database and file storage behind every account — documents, sources, uploads and the audit log.
  • VercelApplication hosting and request logs. Every page and API request is served through Vercel.
  • Lemon SqueezyMerchant of record for paid plans: checkout, card processing, invoices and tax. Card details never reach Folio.
  • LiveKitAudio and video transport for live class and office-hours sessions, while the session is running.
  • Cloudflare R2Storage for session recordings, deleted after 90 days.
  • DeepgramSpeech-to-text for session recordings, so a class has a searchable transcript. Audio is sent for the request and not kept.
  • ResendDelivery of transactional email — sign-in links, invitations, grade and alert notifications.
  • Upstash RedisRate limiting and short-lived caches. Holds request counters, not content.
  • PostHogOpt-in product analytics — which features get used. No document content, and nothing at all until you consent.
  • Anthropic, OpenAIAI features — claim checks, summaries, drafting help. Content is sent for the request and is not used to train models.
Full register, with each vendor's own privacy policy

Export guarantee

An institution's full export — roster, catalog, curriculum, enrollments, grades, course content, registration history and the audit trail — is generated from a declared manifest, so a table added to the product tomorrow is in the export the day it ships, not whenever someone remembers to update a script.

A single person's subject-access export works the same way against their own tables: a machine-readable, versioned bundle (a manifest and one file per table) they or an admin can request without a support ticket. Any individual student can also export their own account's content directly from Settings → Account, anytime, without asking an admin first.

Retention & erasure

Deleting an account removes personal data and content within 30 days, except where compliance requires retention.

For an institution, two retention windows are configurable per-tenant rather than fixed globally: the audit log (minimum 90 days — an audit trail shorter than that would defeat its own purpose) and the archive kept after an erasure request (minimum 30 days, so the institution can still show what was erased and when). Either can be set as long as 3,650 days, or to keep indefinitely, and a legal hold can pause deletion entirely during litigation or an investigation.

An erasure request removes the specific records it targets and leaves a pre-erasure archive behind for the institution's own retention window above — so what was erased, and that it was erased, stays provable without the original content surviving in the live tables.

What we are not yet certified for

Folio has no SOC 2 report, no ISO 27001 certification, and no other third-party conformance report today. We say this plainly rather than let a badge imply otherwise. The architecture is built to a GDPR-aligned standard — row-level security enforced in the database itself, the export and erasure guarantees above, no sale of data, no training of models on your content — and a Data Processing Agreement is available on request. There is no committed target date yet for a formal certification; that is an open question for Folio's security roadmap, not a claim this page will get ahead of.

Support promise

Support is a person, not a ticket queue: email through /contact reaches someone who can actually answer, including questions from a security or data-protection reviewer. Folio does not yet publish a quantified response-time commitment (an SLA) for institutional accounts — worth asking about directly if your procurement process requires one in writing.

Need this for a security review?

Ask us for the DPA and the full subprocessor register — we'll send both, and answer whatever your data-protection office still needs.

Contact us