Forsyt now has a store. Bring your idea and build a Micro SaaS with us, from PRD to launch.

Open the Micro SaaS Store
Enterprise-grade trust

Security and Data Privacy, by design

Revenue data is the most sensitive asset your company owns. Forsyt is engineered so it never leaves your control, by architecture, by contract, and by process.

ISO 27001 CERTIFIED AES-256 IN TRANSIT & AT REST TLS 1.3 TRANSPORT GDPR COMPLIANT ROLE-BASED ACCESS MUTUAL NDA REQUIRED
ISO 27001
Certified

ISO/IEC 27001:2022

Our Information Security Management System is independently audited and certified against the international standard for information security. Scope covers the Forsyt Revenue OS platform and all supporting business functions.

Standard: ISO/IEC 27001:2022 · Last review: Feb 2026

GDPR
Compliant

EU GDPR & UK DPA 2018

Compliant data processor for revenue data of EU and UK residents. SCCs in place for cross-border transfers; DPA available on request.

Read GDPR section
Four pillars

How we protect your data

Zero-Data-Retention

Prompts and responses are processed in-memory. Nothing is persisted on Forsyt servers after a session completes.

  • In-memory only
  • No LLM fine-tuning on your data
  • Ephemeral processing

Legally Bound via NDA

Every engagement begins with a mutual NDA. Your pipeline data stays confidential by contract, not just by policy.

  • Mutual NDA at kickoff
  • Named contract owner
  • Audit-ready provenance

Deploy on Your Terms

Hosted in our managed AWS cloud (EU / India / US regions) by default. Private VPC and on‑prem deployments available on request for Enterprise contracts.

  • Managed AWS hosting
  • Private VPC on request
  • On-prem evaluated case-by-case

Partner-Led Setup

A named technical contact from Forsyt owns every rollout. No self-serve surprises, no hidden data flows, no ambiguity.

  • Named technical contact
  • Security review onboarded
  • White-glove rollout
Controls inventory

The controls we run by default

A snapshot of technical controls applied to every customer, on day one.

AES-256 encryption

All data encrypted in transit (TLS 1.3) and at rest (AES-256).

Role-based access control

Granular RBAC for production access. Google Workspace SSO available today; SAML 2.0 / OIDC on the Enterprise roadmap.

Isolated tenancy

Logical tenant isolation on shared infrastructure today. Single-tenant private VPC deployments available on request for Enterprise contracts.

Provenance-aware AI

AI Deal Chat is grounded in your pipeline context. Source citation for every insight is an active product priority.

In-memory processing

Prompts, responses, and intermediate computations exist only for the session lifetime.

Mutual NDA first

No data, no pilot conversation, no access, until both sides have signed a mutual NDA.

Data lifecycle

What happens to a piece of data inside Forsyt

Five stages, in-memory only, with nothing persisted along the way.

1
Intake

Data enters Forsyt through an authenticated API call from your CRM, call system, or email server.

2
Process

Relevant fields are read in-memory, classified, and transformed into structured signals.

3
Reason

LLM reasoning happens in an isolated session, prompts and context stay within your tenant boundary.

4
Return

Outputs are surfaced in the Forsyt UI. CRM write-back is available where the integration is enabled by your admin, with explicit field-level scope.

5
Purge

Session memory is flushed. Only the final field updates (already yours) remain, in your CRM, not ours.

Security FAQ

Questions security teams ask us first

Do you train AI models on our data?+

No. Customer data is never used to train or fine-tune shared models. All reasoning happens against your tenant context in-memory, and is discarded after the session.

Where is my data processed?+

By default, in our hosted AWS cloud region closest to you (AWS Mumbai for India, AWS Frankfurt for EU, AWS Virginia for North America on request). Private VPC and on-prem deployments are available on request for Enterprise contracts.

What certifications do you hold today?+

Forsyt is ISO/IEC 27001:2022 certified, our Information Security Management System (ISMS) covers the design, development, hosting, and operation of the Forsyt Revenue OS platform and supporting business functions. We are GDPR compliant for EU/UK customers (see GDPR section above). Our certificate, scope statement, Statement of Applicability (SoA) summary, and security-onboarding pack are available on request under NDA.

Do you integrate with our SSO / identity provider?+

Google Workspace SSO is available today. SAML 2.0 and OIDC support (Okta, Azure AD, custom IdPs) is on our Enterprise roadmap and can be prioritised as part of a pilot scoping conversation.

How do you handle data deletion?+

Any field change Forsyt writes to your CRM can be reverted. Session context, transcripts, and intermediate prompts are never persisted to begin with.

Can we review your architecture before pilot?+

Yes. We share a Security Overview document on request (privacy@forsyt.com) covering data flow, control posture, and threat model. We also welcome deep-dive sessions with your security team.

EU & UK customers

GDPR Compliant by architecture and contract

Forsyt processes personal data in line with the EU General Data Protection Regulation (Regulation 2016/679) and the UK Data Protection Act 2018. We act as a data processor for our customers; you remain the data controller for the revenue data we process on your behalf.

Your rights as a data subject

  • Right of access
  • Right to rectification
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Right not to be subject to automated decisions
  • Right to lodge a complaint with a supervisory authority

Lawful basis & data residency

  • Lawful basis: contract performance (Art. 6(1)(b)) for service provision; legitimate interest (Art. 6(1)(f)) for security and abuse prevention.
  • Data residency: EU and UK customer data is processed in AWS Frankfurt (eu-central-1) by default. On-prem and customer-VPC deployments available.
  • International transfers: covered by Standard Contractual Clauses (SCCs) where applicable, with supplementary technical measures.
  • Breach notification: we notify affected customers within 72 hours of any confirmed personal-data breach, per Art. 33.

Data subject requests are acknowledged within 5 business days and resolved within the GDPR’s one-month statutory window. Complex requests may extend by up to two further months with notice.

GDPREUCOMPLIANT

EU GDPR & UK DPA 2018

Compliant data processor for revenue data of EU and UK residents.

Lawful basisArt. 6(1)(b)/(f)
Last reviewFeb 2026
Trust Center

The answer to every security question your procurement team will ask

Instead of filling out a 200-question vendor questionnaire, point your buyer here. Every answer is committed to in writing and grounded in what Forsyt actually does.

Data handling

Where data lives, how it is encrypted, and what we do, and do not, do with it.

Where is our data physically stored?+

EU and UK customer data is stored in AWS Frankfurt (eu-central-1). Indian and APAC customer data is stored in AWS Mumbai (ap-south-1). North American customers can opt for AWS Virginia (us-east-1). Customer choice is set during onboarding and is contractually fixed thereafter.

Is data encrypted at rest? With what?+

Yes. AES-256 encryption at rest using AWS KMS-managed keys.

Is data encrypted in transit?+

Yes. TLS 1.3 for all client-server traffic. TLS 1.2+ for service-to-service traffic inside our VPC. HSTS enforced on all customer-facing endpoints.

Do you train AI models on our data?+

No. Forsyt uses Anthropic Claude (Sonnet) for AI Deal Chat reasoning. Anthropic's commercial terms guarantee zero training on prompts or responses sent through their API. Our backend processes prompts in-memory only, nothing is persisted to Forsyt servers after the response is returned.

How long is data retained? What is your deletion process?+

Customer pipeline data is retained for the duration of the contract. AI conversation context is in-memory only, discarded at session end. Application logs are retained for as long as operationally needed and then purged. On contract termination, all customer data is deleted within 30 days. A signed deletion certificate is provided on request.

What happens to our data if we terminate?+

You receive an export of your pipeline data within 5 business days of the termination notice (CSV / JSON / direct CRM write-back). 30 days post-termination, we purge our active store. 60 days post-termination, we purge all backup copies. Deletion certificate provided.

Will our data leave the EU/EEA?+

For EU/UK customers: no. Application processing, AI inference (Anthropic EU residency), and storage all stay in eu-central-1 / EU. The only exception is engineer access for support, governed by Standard Contractual Clauses and minimised by least-privilege RBAC.

Do you anonymize or pseudonymize personal data?+

Personal data inside customer pipelines is processed as-is (we are the processor, you are the controller, pseudonymization is your choice as controller). Internal product analytics use a one-way hash of user ID and never include pipeline data.

Sub-processors & vendor management

Every third party that touches your data, what they do, and where they live.

Provide a list of all sub-processors+

See /sub-processors for the live list with vendor, purpose, data accessed, hosting region, and DPA link for each. Notable entries: AWS (hosting), MongoDB Atlas (database), Anthropic (LLM), Slack (internal lead-capture), PostHog (anonymized analytics).

For each sub-processor: what data, what purpose, where hosted?+

AWS: encrypted hosting (EU/IN/US). MongoDB Atlas: encrypted DB cluster (same regions). Anthropic: prompt-only LLM inference (zero retention, EU residency available). Slack: lead-capture webhook only (does not receive customer pipeline data). PostHog: anonymized product telemetry (EU). GA/GTM: marketing-site analytics only, post-consent.

Will you notify us before adding a new sub-processor?+

Yes. 30-day advance notice via email (and in-app banner) before any new sub-processor goes live. You have a contractual right to object; objection triggers a good-faith remediation discussion.

Access controls & internal security

Who at Forsyt can touch your data, and how we make sure they never do without reason.

Who at your company can access our data?+

Production data access is restricted to the founder and the designated technical lead. All access is least-privilege and time-bounded, engineers do not have standing access to production. Production access events are logged for audit.

Do you use SSO internally?+

Yes. Forsyt operator access to production systems is gated by Google Workspace SSO. There is no shared or password-only access path to production infrastructure.

Do you log all access to customer data?+

Yes. Application-level access logs (who, what, when, why) are retained for audit. AWS CloudTrail logs cloud-infrastructure events.

Do you do background checks on engineers?+

For permanent engineering hires with production access, we will run standard employment background checks (employment and education verification) prior to provisioning access. As a small team we will share our hiring screening posture with you during pilot scoping.

Compliance & certifications

What we hold today, and what we deliberately do not claim until it is true.

Are you ISO 27001 certified?+

Yes. Forsyt is ISO/IEC 27001:2022 certified. Our Information Security Management System (ISMS) covers the design, development, hosting, and operation of the Forsyt Revenue OS platform and supporting business functions. The certificate, scope statement, and Statement of Applicability (SoA) summary are available on request under NDA.

Are you GDPR compliant?+

Yes. We are a GDPR-compliant data processor. Lawful basis, sub-processors, data residency (AWS Frankfurt for EU), 72-hour breach notification, and the full set of data subject rights are documented above (see GDPR section). DPA available on request to privacy@forsyt.com.

Do you have a Master Services Agreement (MSA) we can sign?+

Yes. Forsyt maintains an MSA template covering the commercial framework, Order Forms, fees, IP, liability, termination, governing law (India / New Delhi), and exhibits for the DPA, NDA, and SLA. We share it with enterprise prospects on request to legal@forsyt.com after a mutual NDA is in place. We are happy to redline against your paper if you prefer to lead with your template.

Have you ever had a data breach?+

No. There has been no confirmed breach of customer personal data since Forsyt was founded. If one ever occurs, our breach notification process notifies affected customers and supervisory authorities within 72 hours.

GDPR-specific

Our processor commitments, your data subject rights, and how to exercise them.

Are you a controller or processor?+

Forsyt is a data processor for the customer pipeline data we process on your behalf. You are the data controller. Forsyt is a data controller only for our own marketing-site visitors and lead-form submissions, covered separately in our public Privacy Policy.

Do you have a DPA we can sign?+

Yes. Email privacy@forsyt.com or click "Request our DPA" above and we will share it within one business day. Standard Contractual Clauses are annexed for any non-EEA transfers.

How do you handle data subject access requests (DSARs)?+

For requests originating with you (our customer): we work with you to fulfil them, your admin can export, rectify, or delete records via the application, and we assist on anything not yet self-serve. For requests originating from a data subject directly to Forsyt: we forward to you (the controller) within 5 business days and assist as required.

What is your breach notification SLA?+

72 hours from confirmed awareness of any personal-data breach, per GDPR Art. 33. We notify the controller (you) and the relevant supervisory authority.

Who is your DPO?+

Udit Pandoh (Founder) acts as Data Protection Officer for Forsyt. Reachable at privacy@forsyt.com. As we scale we may designate a dedicated external DPO; you will be notified contractually if that changes.

Do you do Data Protection Impact Assessments (DPIAs)?+

For any new processing activity classified as high-risk under GDPR Art. 35 (e.g., processing of special-category data, large-scale monitoring), we will work with you on a customer-specific DPIA scoped to the activity. Our internal DPIA approach is in development; we will share its current form on request.

Are international transfers covered?+

EU customers: data does not leave the EEA by default. For any incidental transfer (e.g., engineer access from outside EEA for support), Standard Contractual Clauses apply with supplementary technical measures (encryption at rest, encryption in transit, role-based access).

How do data subjects lodge a complaint?+

Data subjects may complain to their national supervisory authority (e.g., the UK ICO at ico.org.uk, or any EEA data protection authority). They may also write to privacy@forsyt.com, we will engage in good faith.

Incident response

What we do when something goes wrong, and how often we drill it.

Do you have an incident response process?+

Yes, a documented incident-response process covering detection, containment, eradication, recovery, lessons-learned, and customer / regulator notification within the 72-hour GDPR window. The runbook is in active development and will be shareable in redacted form under NDA as it matures.

How do you detect security incidents?+

AWS-native security signals (CloudTrail, VPC flow logs, IAM anomaly alerts), application-level audit logs, dependency-scan alerts, and customer-reported issues via privacy@forsyt.com. We are evaluating AWS GuardDuty and a managed SOC for the next scale stage.

Do you run security exercises?+

The founder and the designated technical lead run informal walk-throughs of incident scenarios. As the team grows, this becomes a formal cross-functional tabletop on a defined cadence.

List security incidents in the past 12 months+

No customer-impacting security incidents to date. If one ever occurs, our breach notification process notifies affected customers and supervisory authorities within 72 hours.

AI / LLM specific

Newer questions every modern security review now includes, answered honestly.

Which LLM do you use?+

Anthropic Claude (Sonnet model family). We chose Anthropic specifically because their commercial terms include zero training on customer prompts/responses, EU data residency is available, they have a public DPA, and they participate in the EU AI Act compliance framework. Model can be switched or co-located on customer infrastructure for Enterprise deployments.

Is the LLM hosted by you or a 3rd party?+

Hosted by Anthropic via their public API today. For Enterprise contracts we are open to scoping alternative deployments (e.g., Anthropic via AWS Bedrock in a dedicated VPC, or evaluating self-hosted open-source models inside your infrastructure), selection happens during contracting and is subject to mutual scoping.

Is there a Data Processing Addendum with Anthropic?+

Yes. Anthropic's commercial DPA covers our use of their API. Their DPA includes SCCs for non-EEA transfers and zero-training commitments. Available for review on request.

Can the LLM regenerate our data when prompted by another customer?+

No. Two reasons: (1) Anthropic does not train on customer API prompts, so your data does not enter their model weights; (2) every customer's session is isolated, prompts include only your tenant's context, never another customer's data.

Are you transparent about AI vs. human decisions?+

Yes. Every AI-generated insight in Forsyt is labelled as such and cites its source data (call, email, CRM event, timestamp). Decisions that materially affect a deal, close-date push, status change, are always reviewed by a human before being written back to your CRM.

Operational

Uptime, recovery, and the boring-but-critical operational metrics.

What is your uptime target?+

Uptime targets are defined per Enterprise order form, with service credits negotiated as part of the contract. Our internal target is 99.9% monthly availability on the production platform.

How is uptime measured?+

Continuous synthetic and live monitoring on all production endpoints. We share monthly availability summaries with Enterprise customers on request. A public status page is in preparation.

Disaster recovery, RTO and RPO?+

Continuous backups with point-in-time restore in MongoDB Atlas. Recovery targets are documented internally and negotiated per Enterprise order form.

Vulnerability management, CVE patch SLAs?+

Critical and high-severity CVEs are prioritised and patched promptly. Lower-severity vulnerabilities are addressed in the standard release cycle. Automated dependency scanning runs against the codebase.

Review our controls before your pilot

Download the Security & Trust Overview and the mutual NDA. We'll walk your security team through architecture and threat model on a 30-minute review call.

Or · All engagements begin with a mutual NDA

We use cookies for analytics to improve your experience. No personal data is sold. Privacy Policy