Security & Data Protection
Follix is engineered to protect commercial sales relationships and deal data with enterprise-grade defensive practices.
All client traffic is strictly routed via TLS 1.3 with modern cipher suites and automated HTTPS enforcement.
User passwords are encrypted with salted cryptographic hashing. Plaintext credentials are never stored or logged.
Databases reside in private virtual networks protected by rigorous least-privilege firewalls with daily encrypted snapshots.
Payment details are processed entirely via Stripe. Full credit card numbers never touch or reside on our servers.
Transport & Hosting Infrastructure
Follix runs on modern, Tier-IV cloud data centers equipped with round-the-clock physical security, environmental controls, biometric access restrictions, and redundant power arrays.
In-flight communications utilize TLS 1.3 encryption with strict HTTP Strict Transport Security (HSTS) headers enabled to block man-in-the-middle attacks and packet sniffing.
Authentication & Session Security
Account authentication utilizes time-limited, digitally signed cryptographic bearer tokens. Sessions expire automatically upon period inactivity or manual logout.
Failed authentication attempts are subject to automated rate-limiting to defend against credential-stuffing and brute-force dictionary attacks.
Data Storage & Backups
Customer pipeline records are stored in managed PostgreSQL instances with encrypted storage volumes (AES-256). Direct public access to production databases is strictly prohibited; all access occurs via internal private networks.
Automated encrypted snapshots are generated daily and retained on a rolling 30-day schedule with point-in-time recovery capabilities to prevent accidental data loss.
Payment Processing Compliance
Follix offloads all credit card handling to Stripe, a certified PCI-DSS Level 1 service provider. Sensitive payment credentials (card numbers, security CVV codes) are transmitted directly from your client browser to Stripe and never touch Follix servers.
Responsible Vulnerability Disclosure
We welcome reports from independent security researchers. If you identify a potential security vulnerability in Follix, please report it immediately:
Security Operations Team
Email: security@follix.io
Please include clear reproduction steps, endpoint URLs, and payload examples.
We pledge to acknowledge submissions within 48 business hours and will not pursue legal action against researchers acting in good faith in accordance with responsible disclosure principles.
Have questions regarding legal policies or data privacy?
Find product guidance in our help center or contact us.