01Summary
We would rather lose a deal at the first search than at the security review — and rather that than be the reason someone ends up out of compliance without knowing it. If a regime below is a hard requirement for you, we are not the right product yet, and saying so here is cheaper for both of us.
| Regime | Status | What that means for you |
|---|---|---|
| HIPAA | Not supported | No BAA. PHI must not be stored. |
| FedRAMP | Not authorized | Not available for US federal use. |
| SOC 2 | No report | No Type I or Type II audit has been performed. |
| ISO 27001 | Not certified | No certification, no Statement of Applicability. |
| PCI DSS | Out of scope | Card details go to Stripe and never reach RowFold. |
| GDPR / UK GDPR | Obligations apply | We act as processor for workspace content; see section 05. |
02HIPAA
RowFold is not HIPAA-capable, and we do not sign Business Associate Agreements. Do not store protected health information in a RowFold workspace.
This is worth being precise about, because "HIPAA compliant" is a claim vendors make loosely. Under HIPAA a vendor handling PHI on a covered entity's behalf is a Business Associate, and that status is created by a signed agreement carrying specific obligations — administrative, physical and technical safeguards, breach notification within defined timeframes, and equivalent agreements flowed down to every subprocessor that could touch the data. It is a contractual and operational programme, not a feature.
We have not entered those agreements, so no configuration of RowFold makes it lawful to store PHI here. If you are a covered entity or a business associate yourself, treat RowFold the way you would any unapproved SaaS tool: fine for operations that never touch patient data, unsuitable for anything that does.
03FedRAMP & government
RowFold has no FedRAMP authorization — no Authority to Operate, no agency sponsor, and no listing in the FedRAMP Marketplace.
FedRAMP authorization is granted, not declared. It requires a full control implementation assessed by an accredited third-party assessment organization, sponsorship by a federal agency or the Joint Authorization Board, and continuous monitoring afterwards. A vendor cannot self-certify, and describing an unauthorized product as FedRAMP-anything would misrepresent a government programme.
RowFold also runs in commercial Azure regions rather than a government cloud, and holds no ITAR, CJIS, or CMMC posture. It should not be used for federal, state or local government data with any handling requirement attached to it.
04SOC 2 & ISO 27001
No audit has been performed against either framework, so there is no report to share and no bridge letter. We are not in an observation window, and we will not describe ourselves as "SOC 2 aligned", "pursuing SOC 2", or any of the other phrasings that sound like an audit without being one.
What does exist is a documented description of the controls actually implemented, on the security page, written to be checked rather than admired. It is self-reported. That is a weaker thing than an audit and we are not going to present it as an equivalent one.
05GDPR & UK GDPR
For the content you put in your workspaces, you are the controller and RowFold is the processor. For your own account and our marketing site, we are the controller. The Privacy Policy covers lawful bases, retention, and how to exercise access, correction, deletion and portability rights — all of which are self-service in the product under Settings.
Two limits worth stating up front: RowFold is operated from the United States, so using it involves an international transfer for EU and UK customers; and we do not currently offer EU data residency. If your assessment requires data to stay in the EEA, that is not something we can accommodate today.
06Subprocessors
The third parties that can process customer data in the course of running RowFold:
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Microsoft Azure | Hosting, database, file storage | All workspace content |
| Anthropic | AI features, per request | Only the data relevant to the request you made |
| Stripe | Billing | Billing contact and payment details — never RowFold workspace content |
| Mailchimp Transactional | Transactional email | Recipient address and message content |
AI calls are made per request and your content is not used to train general-purpose models. We will update this list before adding a new category of subprocessor.
07Data location & retention
All data is stored in the United States, encrypted in transit and at rest. There is no choice of region and no customer-managed encryption keys. Retention, deletion timelines and backup windows are set out in the Privacy Policy; export and account deletion are both self-service rather than a support request.
08Answering a questionnaire
If you have a vendor security questionnaire, send it to security@rowfold.com and we will complete it. Two things to expect: the answers will be self-attested, because there is no audit behind them; and where the honest answer is "no", it will say no rather than "compensating control".
If a certification on this page is a gating requirement for your organisation, it is worth telling us — knowing which regime blocks which buyer is how we decide what to pursue first.
09Contact
Compliance and security questions: security@rowfold.com. Privacy and data-subject requests: privacy@rowfold.com. Postal: RowFold Inc., 14 Cedar Ave, Suite 200, Portland, OR 97214, USA.
Related: Security · Privacy Policy · Terms of Service