generated: '2026-09-19' method: searched source: https://www.fodda.ai/compliance-dossier + https://www.fodda.ai/iso-42001-compliance + https://www.fodda.ai/security + https://www.fodda.ai/blog/security-refresh-2026 + fodda-mcp SECURITY_SUMMARY.md / SECURITY_PACK.md checked: '2026-09-19' summary: 'Fodda publishes a procurement-facing "Compliance Dossier — MCP Server & API Governance" (tool surface and write capability, data handling and training use, authentication and credential scope, assurance position, security contacts; last updated 2026-08-27) and an ISO/IEC 42001 alignment page with an Annex A control mapping. No certification is held or claimed: the assurance position is ALIGNMENT with ISO/IEC 42001:2023 and NIST AI RMF, a NIST CSF 2.0-aligned program, and a SOC 2 Type II readiness roadmap for Q4 2026; the only SOC 2 report cited is Clerk''s (the delegated identity provider). Recorded as a published compliance program without certifications — the Compliance pointer rests on the program, the TrustCenter pointer on the dossier.' portal: url: https://www.fodda.ai/compliance-dossier provider: self-hosted page last_updated: '2026-08-27' audience: InfoSec and IT procurement teams sections: - 1. Tool Surface & Write Capability - 2. Data Handling & Training Use - 3. Authentication & Credential Scope - 4. Assurance Position & Governance - 5. Security Contacts certifications_held: [] alignment_claims: - framework: ISO/IEC 42001:2023 status: alignment (not certified) url: https://www.fodda.ai/iso-42001-compliance last_updated: '2026-08-27' evidence: 'Annex A control mapping: A.5 AI System Life Cycle (read-only tool contracts, deterministic execution); A.6 Data for AI Systems (usage logging ledger, zero model training on client queries); A.7 Information for Interested Parties (provenance & evidence chain); A.8 Responsible Use (automated behavioral test checks); A.9 Third Parties (graceful model degradation error bounds).' - framework: NIST AI RMF status: alignment url: https://www.fodda.ai/compliance-dossier - framework: NIST CSF 2.0 status: program aligned url: https://www.fodda.ai/blog/security-refresh-2026 date: '2026-02-12' - framework: SOC 2 Type II status: readiness roadmap — target Q4 2026 url: https://www.fodda.ai/blog/security-refresh-2026 delegated_assurance: - vendor: Clerk role: identity / authorization server (clerk.fodda.ai) claim: no password custody, SOC 2 Type 2 held since May 2022 source: https://www.fodda.ai/compliance-dossier - vendor: Google Cloud Platform role: 'hosting (Cloud Run / App Engine — server: Google Frontend)' source: https://www.fodda.ai/blog/security-refresh-2026 - vendor: Stripe role: payments and Shared Payment Tokens source: https://www.fodda.ai/llms.txt data_handling: retention: Query text retained in an internal usage ledger for 12 months for billing and telemetry, then purged; result text is not retained. training: Zero model training on client data. options: Zero-retention query logging (in-memory execution), pseudonymous identifiers, and 30-day termination purge available as standard/negotiated contract options. isolation: Per-graph and per-tenant isolation enforced at the API layer (SECURITY_SUMMARY.md); tenant isolation architecture (blog). encryption: TLS 1.2+ in transit (SECURITY_SUMMARY.md); TLS 1.3 observed (security/fodda-ai-domain-security.yml). deployment_options: 'Model B: MCP proxy hosted in the customer''s own Google Cloud project; /enterprises advertises air-gapped on-premise deployments.' contacts: security: security@fodda.ai compliance: compliance@fodda.ai privacy: privacy@fodda.ai legal: legal@fodda.ai related_documents: - name: Security & Procurement Summary url: https://github.com/piers-fawkes/fodda-mcp/blob/main/SECURITY_SUMMARY.md - name: Security Pack url: https://github.com/piers-fawkes/fodda-mcp/blob/main/SECURITY_PACK.md - name: Enterprise MCP Setup url: https://github.com/piers-fawkes/fodda-mcp/blob/main/Enterprise_MCP_Setup.md pointer_basis: 'TrustCenter: the dossier is a real procurement-facing governance page. Compliance: a published, framework-mapped compliance program (ISO 42001 Annex A, NIST) — NOT a certification; readers should not infer SOC 2 / ISO certification from the pointer.'