Security & privacy

Trust is engineered, not claimed.

Follo treats outcome data as infrastructure. This page is maintained by the Follo team to answer common security and privacy questions. It is not an independent certification.

Strict workspace isolation

Every tenant table enforces row-level security. Members only read data inside workspaces they belong to. Guests only see the commitments explicitly shared with them via signed magic links.

Least privilege

Server-side privileged operations run only inside authenticated server functions after role verification. Service credentials never reach browser code.

Consent-gated evidence

Sensitive evidence — including geolocation — requires explicit consent. Attachments are protected with signed URLs and MIME/size validation.

Immutable audit trail

Every acceptance, status change, evidence upload, verification decision, and permission change is recorded with a human-readable summary and technical detail.

No public reputation

Reliability is workspace-private and context-aware. Follo never publishes cross-company reputation scores.

Data control

Workspace admins can export or request deletion of their data. Retention settings live in workspace settings.

Reporting a vulnerability

Email security@getfollo.app. We acknowledge every report and coordinate disclosure with reporters.