Trust, compliance and data location
Last updated October 10, 2026
This page states what WebflowX holds today, what we are working toward, and what we can sign for you. It is updated when something changes. If a statement here and a sales conversation ever differ, this page is the one to hold us to.
1. Certification status
- SOC 2: not audited. We do not hold a SOC 2 Type I or Type II report.
- ISO 27001: not certified.
- What we can show today: the controls described on the Security page, a signed Data Processing Agreement, and the subprocessor list.
2. SOC 2 roadmap
We plan to pursue SOC 2 in stages. We are not publishing dates until an auditor is engaged, because a date we cannot keep is worse than none.
- Written policies. Access control, change management, incident response, vendor review, backup and data retention, each with a named owner.
- Evidence from the product. The audit log, role permissions, two-step verification enforcement, CI test runs and error reporting already produce much of what an auditor asks for. These need to be collected and retained on a schedule.
- Gap assessment. A readiness review by an independent auditor against the Security criteria.
- Type I report, then a Type II observation period.
If SOC 2 is a hard requirement for your purchase, tell us at hello@northfoundry.co. Real demand moves this up the list.
3. Where data is stored
- Database, files and authentication (Convex): a single deployment in the United States (US East). Workspace content, including messages, tasks, notes and uploaded files, is stored there.
- Other processors (hosting, meetings, transcription, AI, email, document collaboration) are listed on the subprocessor page. Where a provider routes traffic is set by that provider.
- Choice of region: not available. There is one deployment for all customers. We cannot today keep a customer’s data in the EU or any other region.
Data may therefore be transferred to the United States. The DPA covers the transfer terms.
4. Retention and deletion
- Deleting a workspace removes its content.
- A member who leaves keeps their channel messages in the workspace, marked as a former member: 90 days on Free, for as long as the workspace exists on paid plans. Their direct messages are removed.
- Owners and admins can export workspace data; anyone can export their own.
- Backups and logs expire on the providers’ regular schedules. We do not offer a configurable retention period or legal hold yet.
5. Incidents
Server errors are reported to us automatically and the service health endpoint is checked on a schedule. If personal data in your workspace is affected by a breach, we notify the workspace owner without undue delay, and within 72 hours of confirming it where the law requires. We do not offer a contractual uptime SLA or a public status page yet.
6. Questions or a security review
Send a questionnaire or question to hello@northfoundry.co. We answer from what is on this site and say plainly when the answer is no.