🔒 Security & trust

Built for the most
sensitive data there is

Faresay handles mental-health information — among the most sensitive categories of personal data. We protect it with a correspondingly high standard, and we're honest about where we are on the journey.

Our role in your data

Faresay is software; the therapist provides the care. Under UK GDPR the therapist is the controller of their clients' clinical data, and Faresay is the processor — we only handle it on their documented instructions, under a Data Processing Agreement. We are the controller of therapist account, billing and usage data.

For employers, that means something practical: you fund and see usage totals — never who attended a session or what was discussed.

🔐

Encrypted everywhere

TLS 1.2+ in transit with HSTS, and AES-256 encryption at rest on the database and backups. Video is carried over an encrypted transport and never stored by us.

🪪

Enterprise SSO & MFA

Sign in with your own identity provider over SAML 2.0 or OIDC — Okta, Microsoft Entra ID, Google Workspace and more. MFA enforced by your IdP is honoured.

🧭

Least-privilege access

Role-based access resolved from our own auditable database — never from IdP-asserted privileges. Strict separation between tenants; admin actions are logged.

💳

We never store card data

Payments are tokenised by Stripe (PCI-DSS Level 1). Card numbers never touch Faresay’s systems.

🇬🇧

UK data residency

Your data is held in a UK region. Where a sub-processor operates outside the UK/EEA, transfers are covered by the UK IDTA / SCC Addendum and a transfer risk assessment.

🛡️

Hardened by default

Strict security headers, server-side validation, cryptographically verified webhooks, and rate-limiting and bot defence that fail closed in production.

For teams & clinics

Single Sign-On, the way your IT team expects

Federate Faresay with your identity provider over SAML 2.0 or OIDC — routed by your email domain, with just-in-time provisioning and your MFA policy honoured. Setup is typically under an hour once we exchange metadata.

Start a security review

A small, vetted set of sub-processors

We keep the list short and choose each provider for its security posture. Customers get at least 14 days' notice before we add a new one.

Neon
Database (UK region)
Vercel
Application hosting
Clerk
Authentication & SSO
Stripe
Payments (PCI-DSS L1)
Daily.co
Secure video
Resend
Transactional email
Twilio
SMS reminders
Plausible
Cookieless analytics

Where we are — honestly

Faresay is early-stage and bootstrapped, and we'd rather tell you exactly where we stand than overstate it. Formal certification is our direction of travel — Cyber Essentials, then ISO 27001, then SOC 2 as we scale — and an independent penetration test is planned around launch. Where a control is inherited from a certified provider (Vercel, Neon, Stripe, Clerk), we can supply theirSOC 2 or ISO 27001 evidence under NDA.

Doing a vendor review?

We'll complete your security questionnaire and share our DPA, sub-processor list and sub-processor certifications under NDA.

security@faresay.com

Privacy policyTermsFaresay for business

← Back home