What Fonteum is · What Fonteum is not
Named public records, with transformations labeled.
What Fonteum does not do
No enrichment. No scoring. No inference.
Data not ingested
Explicit rejection list.
Security posture
No certifications we don't hold.
Fonteum is not SOC 2 attested and does not currently hold a SOC 2 (Type 1 or Type 2), HIPAA, or ISO 27001 attestation, and displays no badge it does not hold. The hosting and data tiers run on SOC 2 Type 2 attested infrastructure (Vercel, Supabase). For procurement requiring a specific attestation, contact security@fonteum.com.
Infrastructure: Vercel (application hosting) + Supabase (managed Postgres, row-level security enforced). Encryption in transit (TLS 1.2+) and at rest. No service-role keys shipped to the browser.
HITRUST i1 evaluation planned for 2027 — i1 (Implemented, 1-year) is the appropriate scope for a no-PHI public-data platform. HIPAA covered-entity status is not applicable — Fonteum processes no PHI.
Vulnerability disclosure: security@fonteum.com · /.well-known/security.txt (RFC 9116).
BAA availability
BAA template on request.
Because Fonteum processes no PHI, BAA execution is typically not required under HIPAA for data ingestion. The template exists as a procurement formality for partners whose internal compliance review requires a signed BAA regardless of processing scope.
Download audit pack (includes BAA template) →Customer evidence
Pilot intake open.
Fonteum does not currently hold SOC 2. Customer evidence published as pilots close. No fake logos, no anonymous testimonials.
Incident disclosure policy
72-hour incident disclosure. Public corrections log.
If a confirmed unauthorized access to user data is discovered, Fonteum notifies affected parties within 72 hours of confirmation and posts a public statement naming the scope of access, the affected data classes, the time window, and the remediation steps taken.
Data-quality incidents (a wrong figure on a live page) follow the same corrections workflow and are logged below alongside doctrinal corrections. Fonteum has not had a breach to date. The policy exists so the threshold is documented.
Selected dated audit note
Public-data corrections and audit notes.
Dated static correction log · 1 entry · not a live source-freshness feed
2026-07-12
Accepted
Public claims audit · Copy correction
Public copy now distinguishes source-release, ingestion, and observation dates. The OIG LEIE production serving table held 68,055 rows from the May 8, 2026 source release when checked July 12; that observation is not a current-file claim.