Compliance

Where we stand, plainly.

What RowFold supports today, what it does not, and which data you should not put in it. Written so a procurement team can get a straight answer without a call.

Last updated · July 31, 2026 · Questions · security@rowfold.com

01Summary

The short version. RowFold signs Business Associate Agreements on request — contact support to start one — so PHI can be stored under a BAA once it is signed. RowFold holds no compliance certifications today and is not FedRAMP authorized. Do not store government data of any classification or payment card numbers in RowFold, and no protected health information until your BAA is signed. Everything else on this page is detail behind that sentence.

We would rather lose a deal at the first search than at the security review — and rather that than be the reason someone ends up out of compliance without knowing it. If a regime below is a hard requirement for you, we would rather say where we stand here than at procurement.

RegimeStatusWhat that means for you
HIPAABAA on requestContact support@rowfold.com; store PHI only once it is signed.
FedRAMPNot authorizedNot available for US federal use.
SOC 2No reportNo Type I or Type II audit has been performed.
ISO 27001Not certifiedNo certification, no Statement of Applicability.
PCI DSSOut of scopeCard details go to Stripe and never reach RowFold.
GDPR / UK GDPRObligations applyWe act as processor for workspace content; see section 05.

02HIPAA

RowFold signs Business Associate Agreements on request. Email support@rowfold.com and we will start one with you. The standard agreement text is published in full so your counsel can read exactly what they would be signing before anyone asks for a signature.

Two things are worth being precise about, because "HIPAA compliant" is a claim vendors make loosely. First, HIPAA has no certification — there is no body that audits a product and pronounces it compliant, so any vendor claiming a HIPAA certificate is describing something that does not exist. What actually exists is the agreement: under HIPAA a vendor handling PHI on a covered entity's behalf is a Business Associate, and that status is created by a signed BAA carrying specific obligations — administrative, physical and technical safeguards, breach notification within defined timeframes, and equivalent agreements flowed down to every subprocessor that could touch the data.

Second, the agreement is what creates the cover, and it covers you only once it is signed by both sides. Asking for one does not. Until your BAA is executed, treat RowFold as you would any tool outside your compliance boundary: fine for operations that never touch patient data, unsuitable for anything that does.

To start, tell us the legal entity that will be named as the covered entity and where the paperwork should go — often legal or privacy rather than the person writing in. We will come back to you on scope and timing before anything is signed.

03FedRAMP & government

RowFold has no FedRAMP authorization — no Authority to Operate, no agency sponsor, and no listing in the FedRAMP Marketplace.

FedRAMP authorization is granted, not declared. It requires a full control implementation assessed by an accredited third-party assessment organization, sponsorship by a federal agency or the Joint Authorization Board, and continuous monitoring afterwards. A vendor cannot self-certify, and describing an unauthorized product as FedRAMP-anything would misrepresent a government programme.

RowFold also runs in commercial Azure regions rather than a government cloud, and holds no ITAR, CJIS, or CMMC posture. It should not be used for federal, state or local government data with any handling requirement attached to it.

04SOC 2 & ISO 27001

No audit has been performed against either framework, so there is no report to share and no bridge letter. We are not in an observation window, and we will not describe ourselves as "SOC 2 aligned", "pursuing SOC 2", or any of the other phrasings that sound like an audit without being one.

What does exist is a documented description of the controls actually implemented, on the security page, written to be checked rather than admired. It is self-reported. That is a weaker thing than an audit and we are not going to present it as an equivalent one.

05GDPR & UK GDPR

For the content you put in your workspaces, you are the controller and RowFold is the processor. For your own account and our marketing site, we are the controller. The Privacy Policy covers lawful bases, retention, and how to exercise access, correction, deletion and portability rights — all of which are self-service in the product under Settings.

The Article 28 terms themselves — our instructions, subprocessor authorisation, breach notification, transfer mechanism and security measures — are published in full as our Data Processing Agreement. It is incorporated into the Terms of Service and applies automatically; there is nothing to request or sign, though we will provide a countersigned copy if your procurement process needs one.

Two limits worth stating up front: RowFold is operated from the United States, so using it involves an international transfer for EU and UK customers; and we do not currently offer EU data residency. If your assessment requires data to stay in the EEA, that is not something we can accommodate today.

06Subprocessors

The third parties that can process customer data in the course of running RowFold:

SubprocessorPurposeData involved
Microsoft AzureHosting, database, file storageAll workspace content
AnthropicAI features, per requestOnly the data relevant to the request you made
StripeBillingBilling contact and payment details — never RowFold workspace content
Mailchimp TransactionalTransactional emailRecipient address and message content
TwilioText messages — booking confirmations and reminders, and automations that send SMSRecipient phone number and message content

AI calls are made per request and your content is not used to train general-purpose models. We will update this list before adding a new category of subprocessor.

07Data location & retention

All data is stored in the United States, encrypted in transit and at rest. There is no choice of region and no customer-managed encryption keys. Retention, deletion timelines and backup windows are set out in the Privacy Policy; export and account deletion are both self-service rather than a support request.

08Answering a questionnaire

If you have a vendor security questionnaire, send it to security@rowfold.com and we will complete it. Two things to expect: the answers will be self-attested, because there is no audit behind them; and where the honest answer is "no", it will say no rather than "compensating control".

If a certification on this page is a gating requirement for your organisation, it is worth telling us — knowing which regime blocks which buyer is how we decide what to pursue first.

09Contact

Compliance and security questions: security@rowfold.com. Privacy and data-subject requests: privacy@rowfold.com. Postal: RowFold LLC, 650 S Pearl St, Columbus, OH 43206.

Related: Security · Privacy Policy · Terms of Service