Trust

Security at fiund.

You are trusting us with archives that took years to build. Here is exactly how they are protected — specifics, not adjectives.

Content storage

  • Contributor content is stored in Amazon S3 with server-side encryption at rest (AES-256) and TLS in transit.
  • Every contributor's files live under an isolated, per-account storage prefix. Upload credentials are scoped so an account can only ever write to — or delete from — its own prefix.
  • There are no public listings. Content is never browsable publicly, and buyers see material only under signed license agreements.
  • Files upload directly from your browser or your own AWS account to storage over TLS — they do not pass through our web servers.

Accounts and data

  • The contributor portal is invite-only. There is no open registration.
  • Every database table is protected by row-level security: each contributor's records — submissions, survey answers, earnings — are readable only by that contributor and fiund staff.
  • Sensitive payout fields (bank account, routing, IBAN, PayPal address) are encrypted at the application layer with AES-256-GCM before they reach the database; only a masked summary is kept readable.
  • Passwords are hashed (bcrypt) by our authentication provider and never stored in plaintext.
  • Agreement signatures are recorded with version, timestamp, IP, and user-agent so both sides have a durable record.

Deletion and withdrawal

  • Contributors can delete their own submissions from the portal at any time — the stored file and the record are both removed.
  • Content withdrawal from the marketplace is a contractual right in the Contributor Licensing Agreement, not a favor.

What we do not claim

We do not currently hold SOC 2 or ISO 27001 certification — few companies our size do, and we would rather tell you that plainly than imply otherwise. As the platform grows, formal certification is on the roadmap. In the meantime, everything above is verifiable in writing in our privacy policy and contributor agreement.

Reporting a vulnerability

If you find a security issue, email jaeden@fiund.com with "Security report" in the subject. We respond within two business days, and we will not pursue good-faith research conducted without harming user data.