Skip to content
Foxx Cyberfoxxcyber/docs

How your data is handled

What vCISO keeps about your business, who processes it, how one business is kept apart from another, how long it is kept, and your choices.

vCISO holds what you tell it about your business, including where your weak spots are. This page sets out, in plain words, what happens to that information. The formal versions are the Privacy Notice and the Terms of Service, and those govern if anything here differs.

What is kept

  • Your account: your name, business name, email address, your password stored only as a one-way hash (it cannot be read back, even by us), and your authenticator secret, stored encrypted.
  • What you tell it: your conversations, and the records it keeps for your business: systems, suppliers, risks, policies, decisions, your limits, and the reports you make.
  • Operational records: which version of the terms you accepted, when, and from which address; sign-in events; your approval decisions; usage counts; and the server logs needed to run and secure the service.

What you tell vCISO and the records it keeps belong to you. Foxx Cyber uses them only to provide the service, keep it secure, and meet legal obligations. We do not sell them, we do not use them for advertising, and we do not use them to train models.

Who processes it

WhoWhat they do
Anthropic, PBCProcesses the content of your conversations to produce your vCISO's answers, under terms that prohibit using that content to train its models.
Railway Corp.Hosts vCISO and its databases in the United States.
Foxx Cyber's portal at foxxcyber.comHandles accounts and billing.
StripeHandles card details, which never reach vCISO.

To answer you, your vCISO sends Anthropic your message and the conversation so far, together with what it knows about your business: your profile, your limits, the systems you depend on, where the six areas stand, and your settings. While it answers, it can look up more of your own records, such as your risk register or policies, and those go to Anthropic too.

Do not enter anything you are not permitted to share with these processors, including controlled unclassified information (CUI), payment card numbers, or health records. CUI work for the Department of Defense belongs in Bedrock CMMC.

Keeping one business apart from another

Every record about your business is tagged with the business it belongs to. When you open a page, the database itself only hands back rows tagged with your business, and it refuses the rest.1 It is not left to each page of the app to remember to filter. If the app ever forgot to say which business it was asking for, the database would return nothing at all, not everyone's records.

Signing in

Every account uses an authenticator app as well as a password. Each code works once, and repeated wrong codes are cut off. Signing out ends your session on every device at once. Password and authenticator resets go through a person at support rather than a button, so knowing a password is never enough to replace your authenticator. See Signing in.

Connections to vCISO are encrypted in transit.

A share link is the only way to see any of your records without signing in. It opens one frozen report and nothing else. The link is shown to you once and stored only in a form that cannot be turned back into the link. Each time it is opened, the service records the visit, with a shortened form of the reader's network address and their browser type, so you can see whether it has been read. See Reports and share links.

Support access

To help with a problem, a member of Foxx Cyber support can open a read-only view of your account. They must give a reason, the view lasts at most an hour, and each one is logged. They cannot change your records or talk to your vCISO as you.

How long it is kept

For as long as your account is open. When it closes, your records are deleted within ninety days, except what the law requires us to keep. Server logs are kept for a limited period for security and then deleted.

There is no button to delete a single conversation. To have something removed, write to support.

Your choices

  • Keep a copy. Print the one-page summary or a report to save it as a PDF.
  • See, correct, or delete what we hold about you, or close your account, by writing to support@foxxcyber.com.
  • Stop your vCISO adding to your business profile by setting Remembering your business to Don't touch it on Settings. Your conversations are still kept. See You decide.

If we change the Privacy Notice in substance, we will show you the new version.

Footnotes

  1. For the technically minded: this is PostgreSQL row-level security, forced on every business-scoped table and scoped to one business per database transaction. The service is built to connect as a database role that cannot bypass it, and checks that role when it starts. ↩

Last updated September 30, 2026