Security at Fido
How we protect interpreting agencies, schools, healthcare teams, and the Deaf consumers they serve, at every layer of the platform.
Last updated October 5, 2026
Security overview
Fido protects confidentiality at every layer. We serve interpreting agencies, school districts, and healthcare teams who handle sensitive information, and Deaf consumers who trust us with their schedules, preferences, and accommodations. Security and privacy are foundational to the product, not bolted on. All information in this Security & Trust Policy is current as of the date of this Policy. Fido takes all commercially reasonable efforts to safeguard and encrypt sensitive and personally identifying information. Fido may update and/or adapt its efforts at any time and these changes may not yet be reflected in this Policy.
Security controls
What’s actually in place, in plain terms. For a security reviewer this matters more than any badge.
- Encryption in transit and at rest
- Role-scoped access control across all portals
- Append-only audit log — entries cannot be edited or deleted
- Org-scoped data isolation in a multi-tenant architecture
- Identity separated from profile data; login identity is never exposed to an organization
- Independent deletion of org-scoped data on offboarding
- Soft delete with history versioning
Compliance and certifications
We’re direct about what’s in place today.
Available today
- HIPAA — Business Associate Agreement (BAA) available on request
- FERPA — addendum available on request
- HECVAT Lite — available on request
- Data Processing Agreement (DPA) — available on request
- Subprocessor list — available on request, with advance notice of changes
- Accessibility — built to WCAG 2.2 AA and tested throughout development by people with accessibility expertise; see our Accessibility statement
Aligned today (not independently certified)
- SOC 2 Type II — controls implemented
- ISO/IEC 27001 — information security program aligned to the standard
- WCAG 2.2 AA — built to the standard; our accessibility self-assessment is available on request
Encryption
- In transit: all traffic is encrypted with TLS 1.2 or higher.
- At rest: data, files, and backups are encrypted using AES-256.
- Encryption keys are managed by our cloud provider’s key-management service and rotated on a regular schedule.
Infrastructure and availability
The Fido platform runs on hardened, enterprise-grade cloud infrastructure on Amazon Web Services (AWS); our marketing website is hosted separately on AWS. Database storage is replicated across multiple availability zones, failed application containers are replaced automatically, and the platform is under continuous health monitoring. Our recovery objectives are to restore service within 24 hours with no more than 15 minutes of data loss.
AI and your data
Fido’s built-in AI assistant sends the model only data the signed-in user is already allowed to see, plus the current conversation, to generate a response. During AI assistant sessions, data from other organizations, deleted records, or previous sessions are never used or incorporated. Your data is not used to train AI models, and the AI platform(s) do not train on data submitted through its API. Organizational customers may instead connect their own AI provider key (bring-your-own), in which case AI runs under their own provider account. See the Privacy Policy for the full breakdown.
Access control and authentication
- Single sign-on (SSO): sign in with Google or Microsoft.
- Role-based access: organization admins, schedulers, providers, clients, and consumers each see only what their role allows. For example, a consumer never sees billing, and a client never sees provider pay.
- Least privilege: Fido staff access to production data is limited to those who need it, reviewed periodically, and revoked promptly on role change or departure.
- All access to sensitive data or actions is logged.
Multi-tenant data isolation
Fido is multi-tenant: every organization operates in its own logically isolated environment on shared, continuously maintained infrastructure. One organization cannot see, query, or modify another organization’s data. Data is shared across organizations only when a provider or customer explicitly opts in through the Fido Network model, and only to the extent they choose.
Monitoring, logging, and incident response
We monitor for unauthorized access and anomalous activity, retain audit logs, and respond to security incidents through detection, containment, remediation, and notification. If a security incident affects your data, we will notify affected customers without undue delay and in accordance with applicable law and contractual commitments.
Vulnerability management and testing
- We regularly check and test our system for vulnerabilities through automated scanning and internal review throughout the course of our product development. If any issues are identified, we will act promptly with due diligence.
Backups and resilience
Encrypted backups run continuously and are stored redundantly, so data can be restored to any point in the last 7 days.
People and vendors
Staff with access to customer data are bound by confidentiality obligations.
HIPAA (healthcare)
Where Fido is used to coordinate interpreting for healthcare providers, we can act as a Business Associate under HIPAA. Protected Health Information is encrypted, access-controlled, and access-logged, and staff who may encounter it complete HIPAA training.
FERPA (education)
When school districts and educational institutions use Fido, we can qualify as a service provider under the U.S. Department of Education’s policies regulating school official exceptions, 34 CFR § 99.31. Student education records are used only to provide the service, are never sold or re-disclosed, and are strictly isolated: one district can never see another’s data. We can support district vendor reviews and provide a completed HECVAT on request.
Responsible disclosure
If you believe you have found a security vulnerability, please email security@fetchfido.ai with the details. Please do not publicly disclose the issue until we have had a chance to address it. We commit to acknowledging your report promptly, keeping you updated, and crediting researchers who report responsibly.
Request documentation
Need our BAA, DPA, FERPA addendum, HECVAT Lite, or subprocessor list? Request them here and we’ll follow up.