Forsyt now has a store. Bring your idea and build a Micro SaaS with us, from PRD to launch.
Open the Micro SaaS StoreRevenue data is the most sensitive asset your company owns. Forsyt is engineered so it never leaves your control, by architecture, by contract, and by process.
Our Information Security Management System is independently audited and certified against the international standard for information security. Scope covers the Forsyt Revenue OS platform and all supporting business functions.
Standard: ISO/IEC 27001:2022 · Last review: Feb 2026
Compliant data processor for revenue data of EU and UK residents. SCCs in place for cross-border transfers; DPA available on request.
Read GDPR sectionPrompts and responses are processed in-memory. Nothing is persisted on Forsyt servers after a session completes.
Every engagement begins with a mutual NDA. Your pipeline data stays confidential by contract, not just by policy.
Hosted in our managed AWS cloud (EU / India / US regions) by default. Private VPC and on‑prem deployments available on request for Enterprise contracts.
A named technical contact from Forsyt owns every rollout. No self-serve surprises, no hidden data flows, no ambiguity.
A snapshot of technical controls applied to every customer, on day one.
All data encrypted in transit (TLS 1.3) and at rest (AES-256).
Granular RBAC for production access. Google Workspace SSO available today; SAML 2.0 / OIDC on the Enterprise roadmap.
Logical tenant isolation on shared infrastructure today. Single-tenant private VPC deployments available on request for Enterprise contracts.
AI Deal Chat is grounded in your pipeline context. Source citation for every insight is an active product priority.
Prompts, responses, and intermediate computations exist only for the session lifetime.
No data, no pilot conversation, no access, until both sides have signed a mutual NDA.
Five stages, in-memory only, with nothing persisted along the way.
Data enters Forsyt through an authenticated API call from your CRM, call system, or email server.
Relevant fields are read in-memory, classified, and transformed into structured signals.
LLM reasoning happens in an isolated session, prompts and context stay within your tenant boundary.
Outputs are surfaced in the Forsyt UI. CRM write-back is available where the integration is enabled by your admin, with explicit field-level scope.
Session memory is flushed. Only the final field updates (already yours) remain, in your CRM, not ours.
No. Customer data is never used to train or fine-tune shared models. All reasoning happens against your tenant context in-memory, and is discarded after the session.
By default, in our hosted AWS cloud region closest to you (AWS Mumbai for India, AWS Frankfurt for EU, AWS Virginia for North America on request). Private VPC and on-prem deployments are available on request for Enterprise contracts.
Forsyt is ISO/IEC 27001:2022 certified, our Information Security Management System (ISMS) covers the design, development, hosting, and operation of the Forsyt Revenue OS platform and supporting business functions. We are GDPR compliant for EU/UK customers (see GDPR section above). Our certificate, scope statement, Statement of Applicability (SoA) summary, and security-onboarding pack are available on request under NDA.
Google Workspace SSO is available today. SAML 2.0 and OIDC support (Okta, Azure AD, custom IdPs) is on our Enterprise roadmap and can be prioritised as part of a pilot scoping conversation.
Any field change Forsyt writes to your CRM can be reverted. Session context, transcripts, and intermediate prompts are never persisted to begin with.
Yes. We share a Security Overview document on request (privacy@forsyt.com) covering data flow, control posture, and threat model. We also welcome deep-dive sessions with your security team.
Forsyt processes personal data in line with the EU General Data Protection Regulation (Regulation 2016/679) and the UK Data Protection Act 2018. We act as a data processor for our customers; you remain the data controller for the revenue data we process on your behalf.
Data subject requests are acknowledged within 5 business days and resolved within the GDPR’s one-month statutory window. Complex requests may extend by up to two further months with notice.
EU GDPR & UK DPA 2018
Compliant data processor for revenue data of EU and UK residents.
Instead of filling out a 200-question vendor questionnaire, point your buyer here. Every answer is committed to in writing and grounded in what Forsyt actually does.
Where data lives, how it is encrypted, and what we do, and do not, do with it.
EU and UK customer data is stored in AWS Frankfurt (eu-central-1). Indian and APAC customer data is stored in AWS Mumbai (ap-south-1). North American customers can opt for AWS Virginia (us-east-1). Customer choice is set during onboarding and is contractually fixed thereafter.
Yes. AES-256 encryption at rest using AWS KMS-managed keys.
Yes. TLS 1.3 for all client-server traffic. TLS 1.2+ for service-to-service traffic inside our VPC. HSTS enforced on all customer-facing endpoints.
No. Forsyt uses Anthropic Claude (Sonnet) for AI Deal Chat reasoning. Anthropic's commercial terms guarantee zero training on prompts or responses sent through their API. Our backend processes prompts in-memory only, nothing is persisted to Forsyt servers after the response is returned.
Customer pipeline data is retained for the duration of the contract. AI conversation context is in-memory only, discarded at session end. Application logs are retained for as long as operationally needed and then purged. On contract termination, all customer data is deleted within 30 days. A signed deletion certificate is provided on request.
You receive an export of your pipeline data within 5 business days of the termination notice (CSV / JSON / direct CRM write-back). 30 days post-termination, we purge our active store. 60 days post-termination, we purge all backup copies. Deletion certificate provided.
For EU/UK customers: no. Application processing, AI inference (Anthropic EU residency), and storage all stay in eu-central-1 / EU. The only exception is engineer access for support, governed by Standard Contractual Clauses and minimised by least-privilege RBAC.
Personal data inside customer pipelines is processed as-is (we are the processor, you are the controller, pseudonymization is your choice as controller). Internal product analytics use a one-way hash of user ID and never include pipeline data.
Every third party that touches your data, what they do, and where they live.
See /sub-processors for the live list with vendor, purpose, data accessed, hosting region, and DPA link for each. Notable entries: AWS (hosting), MongoDB Atlas (database), Anthropic (LLM), Slack (internal lead-capture), PostHog (anonymized analytics).
AWS: encrypted hosting (EU/IN/US). MongoDB Atlas: encrypted DB cluster (same regions). Anthropic: prompt-only LLM inference (zero retention, EU residency available). Slack: lead-capture webhook only (does not receive customer pipeline data). PostHog: anonymized product telemetry (EU). GA/GTM: marketing-site analytics only, post-consent.
Yes. 30-day advance notice via email (and in-app banner) before any new sub-processor goes live. You have a contractual right to object; objection triggers a good-faith remediation discussion.
Who at Forsyt can touch your data, and how we make sure they never do without reason.
Production data access is restricted to the founder and the designated technical lead. All access is least-privilege and time-bounded, engineers do not have standing access to production. Production access events are logged for audit.
Yes. Forsyt operator access to production systems is gated by Google Workspace SSO. There is no shared or password-only access path to production infrastructure.
Yes. Application-level access logs (who, what, when, why) are retained for audit. AWS CloudTrail logs cloud-infrastructure events.
For permanent engineering hires with production access, we will run standard employment background checks (employment and education verification) prior to provisioning access. As a small team we will share our hiring screening posture with you during pilot scoping.
What we hold today, and what we deliberately do not claim until it is true.
Yes. Forsyt is ISO/IEC 27001:2022 certified. Our Information Security Management System (ISMS) covers the design, development, hosting, and operation of the Forsyt Revenue OS platform and supporting business functions. The certificate, scope statement, and Statement of Applicability (SoA) summary are available on request under NDA.
Yes. We are a GDPR-compliant data processor. Lawful basis, sub-processors, data residency (AWS Frankfurt for EU), 72-hour breach notification, and the full set of data subject rights are documented above (see GDPR section). DPA available on request to privacy@forsyt.com.
Yes. Forsyt maintains an MSA template covering the commercial framework, Order Forms, fees, IP, liability, termination, governing law (India / New Delhi), and exhibits for the DPA, NDA, and SLA. We share it with enterprise prospects on request to legal@forsyt.com after a mutual NDA is in place. We are happy to redline against your paper if you prefer to lead with your template.
No. There has been no confirmed breach of customer personal data since Forsyt was founded. If one ever occurs, our breach notification process notifies affected customers and supervisory authorities within 72 hours.
Our processor commitments, your data subject rights, and how to exercise them.
Forsyt is a data processor for the customer pipeline data we process on your behalf. You are the data controller. Forsyt is a data controller only for our own marketing-site visitors and lead-form submissions, covered separately in our public Privacy Policy.
Yes. Email privacy@forsyt.com or click "Request our DPA" above and we will share it within one business day. Standard Contractual Clauses are annexed for any non-EEA transfers.
For requests originating with you (our customer): we work with you to fulfil them, your admin can export, rectify, or delete records via the application, and we assist on anything not yet self-serve. For requests originating from a data subject directly to Forsyt: we forward to you (the controller) within 5 business days and assist as required.
72 hours from confirmed awareness of any personal-data breach, per GDPR Art. 33. We notify the controller (you) and the relevant supervisory authority.
Udit Pandoh (Founder) acts as Data Protection Officer for Forsyt. Reachable at privacy@forsyt.com. As we scale we may designate a dedicated external DPO; you will be notified contractually if that changes.
For any new processing activity classified as high-risk under GDPR Art. 35 (e.g., processing of special-category data, large-scale monitoring), we will work with you on a customer-specific DPIA scoped to the activity. Our internal DPIA approach is in development; we will share its current form on request.
EU customers: data does not leave the EEA by default. For any incidental transfer (e.g., engineer access from outside EEA for support), Standard Contractual Clauses apply with supplementary technical measures (encryption at rest, encryption in transit, role-based access).
Data subjects may complain to their national supervisory authority (e.g., the UK ICO at ico.org.uk, or any EEA data protection authority). They may also write to privacy@forsyt.com, we will engage in good faith.
What we do when something goes wrong, and how often we drill it.
Yes, a documented incident-response process covering detection, containment, eradication, recovery, lessons-learned, and customer / regulator notification within the 72-hour GDPR window. The runbook is in active development and will be shareable in redacted form under NDA as it matures.
AWS-native security signals (CloudTrail, VPC flow logs, IAM anomaly alerts), application-level audit logs, dependency-scan alerts, and customer-reported issues via privacy@forsyt.com. We are evaluating AWS GuardDuty and a managed SOC for the next scale stage.
The founder and the designated technical lead run informal walk-throughs of incident scenarios. As the team grows, this becomes a formal cross-functional tabletop on a defined cadence.
No customer-impacting security incidents to date. If one ever occurs, our breach notification process notifies affected customers and supervisory authorities within 72 hours.
Newer questions every modern security review now includes, answered honestly.
Anthropic Claude (Sonnet model family). We chose Anthropic specifically because their commercial terms include zero training on customer prompts/responses, EU data residency is available, they have a public DPA, and they participate in the EU AI Act compliance framework. Model can be switched or co-located on customer infrastructure for Enterprise deployments.
Hosted by Anthropic via their public API today. For Enterprise contracts we are open to scoping alternative deployments (e.g., Anthropic via AWS Bedrock in a dedicated VPC, or evaluating self-hosted open-source models inside your infrastructure), selection happens during contracting and is subject to mutual scoping.
Yes. Anthropic's commercial DPA covers our use of their API. Their DPA includes SCCs for non-EEA transfers and zero-training commitments. Available for review on request.
No. Two reasons: (1) Anthropic does not train on customer API prompts, so your data does not enter their model weights; (2) every customer's session is isolated, prompts include only your tenant's context, never another customer's data.
Yes. Every AI-generated insight in Forsyt is labelled as such and cites its source data (call, email, CRM event, timestamp). Decisions that materially affect a deal, close-date push, status change, are always reviewed by a human before being written back to your CRM.
Uptime, recovery, and the boring-but-critical operational metrics.
Uptime targets are defined per Enterprise order form, with service credits negotiated as part of the contract. Our internal target is 99.9% monthly availability on the production platform.
Continuous synthetic and live monitoring on all production endpoints. We share monthly availability summaries with Enterprise customers on request. A public status page is in preparation.
Continuous backups with point-in-time restore in MongoDB Atlas. Recovery targets are documented internally and negotiated per Enterprise order form.
Critical and high-severity CVEs are prioritised and patched promptly. Lower-severity vulnerabilities are addressed in the standard release cycle. Automated dependency scanning runs against the codebase.
Download the Security & Trust Overview and the mutual NDA. We'll walk your security team through architecture and threat model on a 30-minute review call.
Or · All engagements begin with a mutual NDA