Security

Your data, protected.

Fairview is built on a security-first architecture. From encryption to access controls, every layer is designed to keep your operating data safe.

Commitments

How we protect your data

SOC 2 Type II

Fairview is SOC 2 Type II compliant, independently audited for security, availability, and confidentiality controls.

Encryption at rest + in transit

All data is encrypted at rest using AES-256 and in transit using TLS 1.2+. Database backups are encrypted with the same standard.

Role-based access controls

Assign Admin, Editor, or Viewer roles to team members. Control who can modify integrations, dashboards, and account settings.

Data retention policy

We retain your data only while your account is active. Upon cancellation or deletion request, all data is permanently removed within 30 days.

Our Approach

Security is architecture, not a feature

Fairview handles sensitive operating data: revenue figures, margin calculations, pipeline values, and cost structures. We treat every piece of data with the same level of care you would expect from your bank. Security is not a checkbox we complete at the end of development. It is the foundation every feature is built on.

Our infrastructure runs on SOC 2 compliant cloud providers with dedicated virtual private clouds, network segmentation, and automated vulnerability scanning. Every integration uses the minimum permissions required to pull data. For OAuth connections, Fairview requests read-only scopes. For API key connections, we recommend restricted keys with read-only access. We never store raw credentials in application databases.

Internal access to customer data is restricted by role and logged for audit. Engineers do not have standing access to production databases. When access is required for infrastructure maintenance, it is granted through a time-limited approval process and revoked automatically. Every access event is recorded.

We conduct regular third-party penetration tests and maintain a vulnerability disclosure programme. Security patches are applied within 24 hours of identification for critical vulnerabilities. Our incident response plan is tested quarterly, and our SOC 2 Type II audit is renewed annually by an independent auditor.

Data Handling

How your data flows through Fairview

From authentication to your dashboard, every step is encrypted and access-controlled.

1

OAuth Connect

You authorize read-only access via OAuth or paste a restricted API key. Credentials are encrypted immediately and stored in a dedicated secrets manager.

2

Encrypted Sync

Data is pulled over TLS 1.2+ encrypted connections. Only the fields Fairview needs are synced. No bulk data dumps. No unnecessary data collection.

3

Encrypted Storage

Data is stored in AES-256 encrypted databases within SOC 2 compliant infrastructure. Backups are encrypted and stored in a separate geographic region.

4

Your Dashboard

Data is served to your dashboard over HTTPS with role-based access controls. Only team members you have invited can view your operating data.

End-to-end encrypted

Compliance

Standards we meet

SOC 2 Type II

Independently audited annually for security, availability, and confidentiality. Our SOC 2 report is available to customers and prospects under NDA upon request.

GDPR Compliant

Fairview complies with the General Data Protection Regulation. We offer Data Processing Agreements, support data subject access requests, and provide a clear data deletion process.

Data Residency

Customer data is stored in the United States by default. For customers with specific data residency requirements, contact our team to discuss available options for EU-based storage.

FAQ

Security questions

Where is Fairview data stored?

All customer data is stored in SOC 2 compliant data centres within the United States. Data is encrypted at rest using AES-256 and in transit using TLS 1.2+. Database backups are encrypted with the same standard and stored in a separate geographic region.

Who can access my data?

Only you and the team members you invite can access your data through the Fairview dashboard. On our side, access is restricted to a small number of senior engineers who require it for infrastructure maintenance. Every internal access event is logged and audited. No customer data is accessed without a documented reason.

Does Fairview sell or share my data?

No. Fairview never sells, shares, or uses customer data for advertising, model training, or any purpose other than powering your operating dashboard and insights. This is a contractual commitment, not just a policy.

How does Fairview handle security breaches?

Fairview maintains an incident response plan that includes detection, containment, investigation, and notification. In the event of a breach affecting customer data, we notify affected customers within 72 hours via email with a full description of the incident, the data involved, and the remediation steps taken.

Is my data encrypted?

Yes. All data is encrypted at rest using AES-256 and in transit using TLS 1.2+. Integration credentials are encrypted separately from application data and stored in a dedicated secrets manager. Database backups are encrypted with the same standard.

Does Fairview support SSO?

SSO via SAML 2.0 is available on the Scale plan ($699/mo). Growth plan customers can use Google Workspace or Microsoft 365 sign-in. All plans support two-factor authentication.

What about data deletion?

You can request full deletion of your account and all associated data at any time by contacting security@getfairview.com. Deletion is completed within 30 days and includes all synced data, dashboard configurations, integration credentials, and backups. We provide written confirmation once deletion is complete.

Ready to see your data clearly?

Stop reporting on last week.
Start acting on this week.

10 minutes to connect. No SQL. No engineering team. Your first dashboard is built automatically.

No credit card required · Cancel anytime · Setup in under 10 minutes