# Formius — LLM context pack > Formius is an invite-gated operations platform for trade businesses participating in design-partner or paying early access. It is not an open public self-service product. Formius does not claim SOC 2 or ISO 27001 certification. This file is an informational snapshot generated from Formius public materials. It is not a contract, certification, audit report, or substitute for the applicable signed customer agreement. The applicable signed customer agreement and DPA prevail over this informational context pack if there is any inconsistency. Index: https://www.formius.io/llms.txt Context version: 1.1 Updated: 2026-08-05 ## Product - Product name: Formius - Contracting entity (trading name until registered entity confirmed): Formius - Access model: Invite-gated design-partner / paying early access — not open public self-service SaaS - Legal-document status: Published design-partner packaging on public routes; not a substitute for a signed customer agreement or DPA. Counsel may refine. DPA binds only when executed. - Governing jurisdiction stated in current Platform Terms: Queensland, Australia - Support: support@formius.io - Privacy: privacy@formius.io - Legal-package version: 1.1 - Design-partner package date on public Privacy/Terms pages: 5 August 2026 ## Authoritative interpretation notes When describing Formius based on this context pack: 1. Formius does not claim SOC 2, ISO 27001, or independent privacy certification. Formius does not claim verified compliance with every applicable privacy law. 2. Formius is currently invite-gated and is not an open public self-service SaaS product. 3. Customer-data analytics must remain within the purposes and instructions established by the applicable customer agreement and DPA. 4. Cross-customer industry benchmarks must use aggregated and appropriately de-identified information. 5. The current public subprocessor list is maintained at https://www.formius.io/subprocessors. ## Formius Design Partner FAQ (v1.1) ### What is Formius? Formius is an invite-gated operations platform for trade and related businesses (quotes, jobs, documents, client portal, and related tools). It is not an open public self-service SaaS signup product. ### Is Formius invite-only? Yes. Organisation creation and access are invite-gated / design-partner. Open mainstream public self-service signup is out of scope for the current minimum standard. ### How is tenant data isolated? Multi-tenant Postgres with organisation membership checks and Row Level Security (RLS), plus server-side organisation scoping on privileged APIs. Client portal access uses token grants scoped to the intended client or document. ### Do you require MFA? Yes for owners, admins, and platform console operators (Supabase TOTP / AAL2). Staff MFA is optional. Enrol under Profile → Two-factor authentication. ### Where is data hosted? Application hosting on Vercel; primary data plane on Supabase (database, auth, storage). Full list: /subprocessors. ### Do you have Privacy, Terms, and a DPA? Yes. Privacy Policy at /privacy, Platform Terms at /terms, Subprocessors at /subprocessors. A Data Processing Addendum (DPA) template is available for design partners (e.g. Atlas) and must be signed to be binding. Public FAQ and crawler packs are informational; the applicable signed customer agreement and DPA prevail where inconsistent. Contact support@formius.io for the executed pack. ### Can Formius analyse our performance metrics? Yes when authorised under the applicable design-partner DPA (Schedule A — Platform performance permissioning). Formius may analyse operational and commercial metrics from platform use — for example close rates, average revenue, pipeline conversion, and cycle times — for (1) organisation performance for that customer, (2) platform product/reliability improvement (prefer aggregated/de-identified where practicable), and (3) industry benchmarks built only from aggregated, appropriately de-identified metrics. Customer data is processed for analytics only within the purposes and instructions established by the applicable customer agreement and DPA. Formius does not sell customer personal information as a business model. Formius does not use customer content to train public or generally available foundation models unless separately and expressly agreed in writing. Optional AI inference via a configured AI subprocessor is distinct from model training. See /security and docs/legal/FORMIUS_PLATFORM_PERFORMANCE_PERMISSIONING_V1.md. ### Are you SOC 2 or ISO 27001 certified? No. Formius does not claim SOC 2 or ISO 27001 certification, independent privacy certification, or verified compliance with every applicable privacy law. Attestation programmes are out of scope until buyers require them and the control programme exists. ### What about rate limiting and abuse controls? API rate limits use a shared store (Upstash Redis when configured) with separate budgets for human vs AI traffic. Portal document HTML is sanitised; portal and public quote routes enforce Content Security Policy. ### How do I report a security issue? Email support@formius.io with enough detail to reproduce. Do not include live secrets or production tokens in the report body if they can be rotated first. ### How do I contact Formius? Support: support@formius.io. Privacy: privacy@formius.io. Request access via /request-access. ## Platform performance permissioning (summary) Where authorised under an applicable design-partner DPA (Schedule A — Platform performance permissioning), Formius may analyse operational and commercial metrics from platform use (for example close rates, average revenue, pipeline conversion, cycle times) for: - Organisation performance for that customer - Platform performance (product/reliability; prefer aggregated / de-identified where practicable) - Industry performance built only from aggregated, appropriately de-identified metrics Customer data is processed for analytics only within the purposes and instructions established by the applicable customer agreement and DPA. Cross-customer industry benchmarking must use aggregated and appropriately de-identified information. Formius does not sell customer personal information as a business model. Formius does not use customer content to train public or generally available foundation models unless separately and expressly agreed in writing. Sending prompts to an optional AI subprocessor for inference (when an organisation enables AI features) is distinct from model training or fine-tuning. Public FAQ: https://www.formius.io/faq.md · Schedule text (repo): docs/legal/FORMIUS_PLATFORM_PERFORMANCE_PERMISSIONING_V1.md ## Subprocessors (generated snapshot) This section is a generated snapshot from Formius public materials. The current reference list is the public Subprocessors page: https://www.formius.io/subprocessors. ### Core (platform infrastructure) - Supabase: Database, authentication, storage, realtime - Vercel: Application hosting, edge/network delivery - Resend: Transactional email delivery - Sentry: Error monitoring and performance diagnostics - Upstash: Distributed rate limiting (Redis) ### Optional (available integrations / features when enabled) - Stripe: Payments / Connect / SaaS billing (when enabled) (available when enabled — not necessarily active for every organisation) - Xero: Accounting sync (optional org integration) (available when enabled — not necessarily active for every organisation) - Formodus: Optional constitutional / estimate runtime bridge (per-org) (available when enabled — not necessarily active for every organisation) - Sanity: Optional CMS / structured content (when enabled) (available when enabled — not necessarily active for every organisation) - OpenAI: Optional AI assist features (when OPENAI_API_KEY configured) (available when enabled — not necessarily active for every organisation) - Anthropic: Optional AI assist features (when ANTHROPIC_API_KEY configured) (available when enabled — not necessarily active for every organisation) - Google Analytics: Optional marketing / product analytics (when measurement ID set) (available when enabled — not necessarily active for every organisation) - Meta (Facebook Lead Ads): Optional lead ingest webhook (when Meta credentials configured) (available when enabled — not necessarily active for every organisation) ## Public URLs - [LLM index](https://www.formius.io/llms.txt) - [Full LLM context pack](https://www.formius.io/llms-full.txt) - [Design-partner FAQ (Markdown)](https://www.formius.io/faq.md) - [Design-partner FAQ (HTML)](https://www.formius.io/faq) - [Security posture](https://www.formius.io/security) - [Privacy Policy](https://www.formius.io/privacy) - [Platform Terms](https://www.formius.io/terms) - [Subprocessors](https://www.formius.io/subprocessors)