Fromenance

Security

Finished before the first pilot, not after

Fromenance is a communication provenance platform that asks institutions to route customer mail through it, so the security posture below was a requirement before the first pilot rather than a roadmap item. This page says what we store, how long we keep it, how tenants are isolated, and who our subprocessors are; the DPA makes it contractual.

Data handling

What we store and for how long

Data categories and retention
DataFormRetention
Registered communicationVerify code, recipient HMAC, SimHash and SHA-256 fingerprint, message id, From address, sent time, link domains, template and campaign idsTenant retention window, default 90 days
Forwarded or uploaded messageRaw MIME or screenshot, encrypted in R2 under the tenant prefixTenant retention window, default 90 days, deleted with an audit record
Submitter addressHMAC for matching; encrypted copy for the reply onlyEncrypted copy purged 30 days after the reply
VerdictOutcome, rule, signals, matched registration id, override trailLife of the tenant account
IndicatorsKind, normalized value, first and last seen, countsLife of the tenant account
Rejected inboundMail that failed the trust check, with the reason24 hours
Audit logActor, action, target, before and afterLife of the tenant account

Trust and abuse

Platform security

Subprocessors

Nothing runs outside Cloudflare, Neon, and Resend at runtime. Stripe holds billing, Sentry receives error events. Changes are announced to tenants 30 days in advance as described in the DPA.

Subprocessors
SubprocessorPurposeLocation
Cloudflare, Inc.Hosting, edge compute, edge storage (D1, R2, Queues), Workers AI for screenshot OCR, TurnstileUnited States
Neon, Inc.Postgres system of recordUnited States
Resend, Inc.Inbound and outbound emailUnited States
Stripe, Inc.BillingUnited States
Functional Software, Inc. (Sentry)Error monitoringUnited States

Compliance roadmap and disclosure

SOC 2

SOC 2 Type 1 is targeted within 12 months of the first paying tenant. Until then, this page, the DPA, and a completed vendor security questionnaire are what we offer a bank's third party risk review. Ask and we will complete yours.

Responsible disclosure

Report vulnerabilities to security@fromenance.com. We acknowledge within two business days, keep you informed, and do not pursue researchers who act in good faith, avoid privacy violations and service disruption, and give us reasonable time to fix. Please do not test against tenant inboxes or production tenant data; use the demo tenant on this site.

Security incidents affecting a tenant's data are notified to that tenant without undue delay and no later than 72 hours after we confirm them.

Send us your vendor security questionnaire.

We answer it against this page and the DPA. If your review prefers to start without mail routing, the web verify page needs no mail plumbing at all.