Legal

Trust Center

Security is foundational to Fora. We built our platform with privacy-first architecture, zero-retention data handling, and enterprise-grade encryption.

Last updated: December 29, 2024

Compliance Resources

Compliance Status

SOC 2 Type I

In progress. Expected completion: Q2 2025

GDPR Ready

Data processing agreements available. EU data subject rights supported.

Google CASA Tier 2

Cloud Application Security Assessment for restricted OAuth scopes.

Frequently Asked Questions

How is my data protected?

We use AES-256 encryption at rest, TLS 1.2+ for all data in transit, and PostgreSQL row-level security for complete tenant isolation. OAuth tokens are encrypted with per-tenant key material.

What data do you store?

We store vector embeddings, extracted tasks, and metadata. Raw email and document content is processed in memory and immediately discarded. We never persist the actual text of your messages or files.

Who can access my data?

Only you and members of your workspace. Fora employees cannot access customer data without explicit permission. All access is logged and audited.

How do I delete my data?

Go to Settings → Delete Workspace. After re-authenticating with Google, all your data will be permanently removed within minutes. OAuth tokens are revoked before data deletion.

Do you use my data to train AI?

No. Your data is never used to train AI models. We use commercial AI APIs (Anthropic, OpenAI) with enterprise agreements that prohibit training on customer data.

Contact Security Team

For security questions, vulnerability reports, or to request a data processing agreement:

We respond to security inquiries within 24 hours.