About

We're building the operational graph for modern companies.

Most software treats data as a list of disconnected rows. The result: AI that summarizes paragraphs, reports that stop at one hop, and dashboards nobody trusts. RowFold was started because relationships are how companies actually run — and the tooling underneath has never caught up.

Story

Why now.

RowFold started from a pattern anyone who has run an operation will recognise: a Companies sheet, a Deals sheet, a Tasks sheet — each updated by hand, never quite in sync, with reports that take someone a full afternoon to assemble. The work is relational. The tools underneath it are not.

AI is what made the cost of that obvious. An assistant can only be as smart as the model of the business it can actually see, and a folder of disconnected sheets gives it almost nothing to reason about. Answering "which customers are at risk" means traversing relationships, not summarising paragraphs. That's the layer we're building.

Principles

How we work.

Four ideas we keep coming back to.

01

Data shape over feature count.

We resist adding shiny features that don't strengthen the underlying graph. The schema is the product. Everything else is interface on top of it.

02

Honest defaults.

If most users want it on, it's on. If something only makes sense in 5% of cases, it lives behind an explicit toggle. No dark patterns, no confusing menus.

03

Ship to learn.

We move fast on the surface and slowly on the data model — the opposite of most products. Interface decisions are cheap to revisit; the shape of your data is not, so that is where the caution goes.

04

AI is plumbing, not theatre.

AI shouldn't be a feature surfaced everywhere. It should be a quiet capability that gets pulled into the moments where it matters. We hide our AI buttons behind real use cases.

Where things stand

Early, and specific about it.

i
RowFold is a young product. Rather than pad this page with the vague reassurance that usually fills it, we keep the details that actually matter in one place and state them plainly — including the parts that are not in place yet. There is no SOC 2 report, no ISO 27001 certification and no third-party penetration test, and we won't describe ourselves as pursuing one until we are.

The security page covers where data runs and how it is stored and encrypted, and lists the gaps without softening them. The compliance page lists what we hold — currently nothing — along with every subprocessor that touches your data. If the answer you need is missing from either, ask us rather than guess.