Plain-text crawl copy: /faq.md. LLM index: /llms.txt. Full LLM context: /llms-full.txt.
What is Formius?
Formius is an invite-gated operations platform for trade and related businesses (quotes, jobs, documents, client portal, and related tools). It is not an open public self-service SaaS signup product.
Is Formius invite-only?
Yes. Organisation creation and access are invite-gated / design-partner. Open mainstream public self-service signup is out of scope for the current minimum standard.
How is tenant data isolated?
Multi-tenant Postgres with organisation membership checks and Row Level Security (RLS), plus server-side organisation scoping on privileged APIs. Client portal access uses token grants scoped to the intended client or document.
Do you require MFA?
Yes for owners, admins, and platform console operators (Supabase TOTP / AAL2). Staff MFA is optional. Enrol under Profile → Two-factor authentication.
Where is data hosted?
Application hosting on Vercel; primary data plane on Supabase (database, auth, storage). Full list: /subprocessors.
Do you have Privacy, Terms, and a DPA?
Yes. Privacy Policy at /privacy, Platform Terms at /terms, Subprocessors at /subprocessors. A Data Processing Addendum (DPA) template is available for design partners (e.g. Atlas) and must be signed to be binding. Public FAQ and crawler packs are informational; the applicable signed customer agreement and DPA prevail where inconsistent. Contact support@formius.io for the executed pack.
Can Formius analyse our performance metrics?
Yes when authorised under the applicable design-partner DPA (Schedule A — Platform performance permissioning). Formius may analyse operational and commercial metrics from platform use — for example close rates, average revenue, pipeline conversion, and cycle times — for (1) organisation performance for that customer, (2) platform product/reliability improvement (prefer aggregated/de-identified where practicable), and (3) industry benchmarks built only from aggregated, appropriately de-identified metrics. Customer data is processed for analytics only within the purposes and instructions established by the applicable customer agreement and DPA. Formius does not sell customer personal information as a business model. Formius does not use customer content to train public or generally available foundation models unless separately and expressly agreed in writing. Optional AI inference via a configured AI subprocessor is distinct from model training. See /security and docs/legal/FORMIUS_PLATFORM_PERFORMANCE_PERMISSIONING_V1.md.
Are you SOC 2 or ISO 27001 certified?
No. Formius does not claim SOC 2 or ISO 27001 certification, independent privacy certification, or verified compliance with every applicable privacy law. Attestation programmes are out of scope until buyers require them and the control programme exists.
What about rate limiting and abuse controls?
API rate limits use a shared store (Upstash Redis when configured) with separate budgets for human vs AI traffic. Portal document HTML is sanitised; portal and public quote routes enforce Content Security Policy.
How do I report a security issue?
Email support@formius.io with enough detail to reproduce. Do not include live secrets or production tokens in the report body if they can be rotated first.
How do I contact Formius?
Support: support@formius.io. Privacy: privacy@formius.io. Request access via /request-access.
Related pages
- Security FAQ (short security posture)
- Privacy Policy
- Platform Terms
- Subprocessors
- support@formius.io