Security & Privacy
Enterprise-grade security for your marketplace data.
SOC 2 Type II certified, ISO/IEC 27001 certified, and GDPR-compliant, with TLS 1.3 and AES-256 encryption everywhere. The same security posture trusted by Intel, Snowflake, and Fireblocks.
SOC 2 Type II
Annual security audit certification
ISO/IEC 27001
Information security management certified
GDPR
EU data protection compliance
Our security principles
Encryption everywhere
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Your sensitive information is always protected.
Zero-trust architecture
Every request is authenticated and authorized. We follow the principle of least privilege across our entire infrastructure.
Secure infrastructure
Hosted on AWS in the United States across multiple availability zones, with automated backups.
Regular audits
We undergo regular third-party security audits, penetration testing, and vulnerability assessments.
Built for enterprise security teams
Fours provides the controls enterprise security reviews ask for — OIDC SSO, SCIM provisioning, role-based access, and a queryable audit trail.
View Privacy PolicyControls, and which plans have them
Every control below is in effect today. Where a control is limited to a plan, the scope column says so.
| Area | Control | Scope |
|---|---|---|
| Data location | Customer data is stored and processed in the United States, on AWS. | All plans |
| Tenant isolation | Every record belongs to one organization. All API paths are org-scoped, and each request must prove membership of the organization it targets before any data is read. | All plans |
| Authentication | Two credentials: an organization API key, or an OIDC bearer token verified against the issuer's published keys. Identity is never taken from a request header. | All plans |
| Single sign-on | OIDC SSO with SCIM user provisioning, configured self-service in the console. | Growth and Enterprise |
| Multi-factor auth | MFA on user accounts, including administrative reset. | All plans |
| Authorization | Role-based access control with ADMIN, EDITOR and VIEWER roles. No identity is granted editor access across all organizations. | All plans |
| Audit trail | Auditing events are a first-class resource you can query over the API, not just a console view. | All plans |
| Secrets | Credentials are held in a managed secrets service and referenced indirectly. They are not stored in configuration. | All plans |
| Abuse protection | Rate limits guard the partner program's public endpoints — portal sign-in, public forms, invitation links, and the external-LMS webhook — and cap two resource-intensive operations per organization. Each of these limiters fails closed — if it cannot be consulted, the request is rejected rather than allowed. | All plans |
| Webhook integrity | Outbound webhooks are HMAC-signed and carry an X-Suger-Signature-256 header you verify before trusting the payload. | All plans |
| Encryption | TLS 1.3 in transit and AES-256 at rest, with keys managed by the cloud provider's KMS. | All plans |
| Custom security policies | Bespoke controls negotiated as part of an enterprise agreement. | Enterprise only |
Who is responsible for what
Fours is a processor sitting between your systems and the cloud marketplaces. This is where the line falls.
| Area | Fours | You |
|---|---|---|
| Platform, infrastructure and encryption | Runs, patches and monitors the service; manages encryption and key rotation. | None. |
| Who can access your Fours organization | Enforces roles and org boundaries on every request; provides SSO and SCIM. | Decides who is invited, assigns roles, and deprovisions leavers. |
| Marketplace and CRM credentials you connect | Stores them in a managed secrets service and uses them only for your organization's operations. | Grants the narrowest scope that works, and rotates on your own schedule. |
| API keys and OAuth clients | Issues, scopes and validates them. | Keeps them secret, rotates them, and revokes on compromise. |
| What data you send to Fours | Processes it under the DPA and the terms. | Decides what to send; Fours does not require personal data beyond user accounts. |
| Reviewing the audit trail | Records events and exposes them over the API. | Reviews them, and exports to your SIEM if you keep one. |
How your data flows
Fours sits between three parties and holds no data that does not belong to one of those relationships:
- Your systems → Fours. Your CRM, billing and metering systems connect with credentials you authorize per organization. You choose the scope.
- Fours → the marketplaces. Fours calls AWS, Microsoft, Google Cloud, Snowflake, Alibaba Cloud and Oracle on your behalf using the marketplace credentials you connect.
- The marketplaces → Fours → you. Entitlements, usage and disbursement flow back, are reconciled, and are pushed to your finance systems or read over the API.
Every hop is authenticated, scoped to one organization, and recorded in the audit trail. Fours does not require end-customer personal data beyond the user accounts you create.
Requesting evidence
Enterprise customers and prospects under NDA can request the SOC 2 Type II report, the ISO/IEC 27001 certificate, penetration test summaries, and completed security questionnaires. Email [email protected] and state which documents you need and the review deadline.
A Data Processing Agreement is available to all customers — see the privacy policy and GDPR commitment.
Published · Last reviewed
Written and maintained by the Fours team.
Spotted something out of date? Email [email protected] and we will correct it.
Report a security vulnerability
We value the security community's help in keeping Fours and our customers safe. If you discover a vulnerability, please report it responsibly.
Our commitments
What we ask
Security questions, answered
Is Fours SOC 2 compliant? +
Yes. Fours is SOC 2 Type II certified, with annual third-party audits covering security, availability, and confidentiality. The report states the audited scope; it is available to enterprise customers and prospects under NDA from [email protected].
Is Fours ISO/IEC 27001 certified? +
Yes. Fours is certified against ISO/IEC 27001, the international standard for information security management systems (ISMS), covering risk management, access control, and continuous security improvement. The certificate is available to enterprise customers on request.
Is Fours GDPR compliant? +
Yes. Fours complies with GDPR requirements for EU data protection, including lawful processing, data subject rights, and cross-border transfer safeguards. A Data Processing Agreement (DPA) is available for all customers.
How does Fours encrypt customer data? +
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Encryption keys are managed through cloud provider KMS services with automatic rotation.
Where is Fours data hosted? +
Fours runs on AWS in the United States, across multiple availability zones, with automated backups. All customer data is stored and processed in the US today. If your procurement requires data residency in another region, raise it with [email protected] before contracting.
Does Fours support SSO and MFA? +
Yes. Fours supports OIDC single sign-on and SCIM user provisioning, set up self-service in the console, on Growth and Enterprise plans. Multi-factor authentication is available to all users on every plan. If your identity provider requires SAML rather than OIDC, contact [email protected].
Is my data isolated from other Fours customers? +
Yes. Every record belongs to exactly one organization, every API path is scoped to an organization, and each request must prove membership of the organization it targets before any data is read. Identity is never taken from a request header.
Does Fours use my data to train AI models? +
No. Fours does not use your documents or conversations to train AI models. In Insulin, knowledge base content is searched at query time to ground an agent's answer and return cited sources.
Can I see who did what in my Fours account? +
Yes. Auditing events are a first-class resource you can query over the API, not just a console view, so you can export them into your own SIEM or review tooling.
How do I report a security vulnerability? +
Email [email protected] with details of the vulnerability. We acknowledge all reports within 48 hours and coordinate on remediation and disclosure timelines. See our responsible disclosure policy below.
Can I get Fours' security documentation? +
Enterprise customers can request our SOC 2 Type II report, penetration test summary, and security questionnaire responses. Contact [email protected] or schedule a call with your sales rep.
Have security questions?
Our security team is here to help. Request our SOC 2 report, DPA, or schedule a security review.