Trust & security

Care is part of the product.

We use practical safeguards, minimize unnecessary collection, and keep people in control of consequential work.

Protected payments

When checkout opens, payment collection will be hosted by Stripe. Fog & Iron will not receive or store complete payment-card numbers.

Encrypted connections

Our websites and apps use encrypted HTTPS connections in transit. Access to production systems is restricted.

Responsible AI

AI-assisted outputs are designed for review. Products identify missing information and do not promise infallible results.

Limited access

Service providers receive only the information needed to deliver hosting, payment, security, and product functions.

Honest assurance

We do not claim certifications we have not earned.

Fog & Iron Labs is an early-stage company. Our controls will mature with the products and customer needs. Unless a product page or signed agreement expressly says otherwise, our services are not represented as HIPAA-compliant, PCI-certified by Fog & Iron, SOC 2 certified, or suitable for classified information.

Do not upload passwords, payment-card data, Social Security numbers, protected health information, classified material, or other highly sensitive data unless the relevant product expressly supports it.

Report a concern

Security reports are welcome.

Send a clear description, affected URL, reproduction steps, and potential impact. Do not access or alter other people’s data.

security@fogandironlabs.com