This Information Security Policy establishes the framework for protecting Freedom Forge's information assets, systems, and customer data from unauthorized access, disclosure, modification, or destruction.
Company Information:
Protecting sensitive information from unauthorized disclosure
Ensuring accuracy and completeness of information
Ensuring authorized users can access information when needed
Required for all critical systems:
Data in Transit:
Data at Rest:
Customer Financial Data:
Sensitive Credentials:
Application Hosting: Vercel (SOC 2 Type II certified)
Database: Supabase PostgreSQL (SOC 2 Type II certified)
Financial Data Aggregation: Plaid (SOC 2 Type II certified)
Version Control: GitHub (SOC 2 Type II certified)
Critical (Response Within 1 Hour):
High (Response Within 4 Hours):
Medium (Response Within 24 Hours):
Detection:
Containment:
Eradication:
Communication:
Database Backups (Supabase):
Code Repository (GitHub):
Recovery Time Objective (RTO): 4 hours (time to restore service after total system failure)
Recovery Point Objective (RPO): 24 hours (maximum acceptable data loss)
| Provider | Purpose | Compliance |
|---|---|---|
| Plaid | Financial data aggregation | SOC 2 Type II |
| Vercel | Application hosting | SOC 2 Type II |
| Supabase | Database & authentication | SOC 2 Type II |
| GitHub | Code repository | SOC 2 Type II |
Freedom Forge complies with:
Report security incidents or concerns immediately:
Questions about this Information Security Policy:
Policy Owner: Marc Carlton, Founder
Document Version: 1.0
Effective Date: November 26, 2025
Last Reviewed: November 26, 2025
Next Review: May 26, 2026