Faresay handles mental-health information — among the most sensitive categories of personal data. We protect it with a correspondingly high standard, and we're honest about where we are on the journey.
Faresay is software; the therapist provides the care. Under UK GDPR the therapist is the controller of their clients' clinical data, and Faresay is the processor — we only handle it on their documented instructions, under a Data Processing Agreement. We are the controller of therapist account, billing and usage data.
For employers, that means something practical: you fund and see usage totals — never who attended a session or what was discussed.
TLS 1.2+ in transit with HSTS, and AES-256 encryption at rest on the database and backups. Video is carried over an encrypted transport and never stored by us.
Sign in with your own identity provider over SAML 2.0 or OIDC — Okta, Microsoft Entra ID, Google Workspace and more. MFA enforced by your IdP is honoured.
Role-based access resolved from our own auditable database — never from IdP-asserted privileges. Strict separation between tenants; admin actions are logged.
Payments are tokenised by Stripe (PCI-DSS Level 1). Card numbers never touch Faresay’s systems.
Your data is held in a UK region. Where a sub-processor operates outside the UK/EEA, transfers are covered by the UK IDTA / SCC Addendum and a transfer risk assessment.
Strict security headers, server-side validation, cryptographically verified webhooks, and rate-limiting and bot defence that fail closed in production.
Federate Faresay with your identity provider over SAML 2.0 or OIDC — routed by your email domain, with just-in-time provisioning and your MFA policy honoured. Setup is typically under an hour once we exchange metadata.
We keep the list short and choose each provider for its security posture. Customers get at least 14 days' notice before we add a new one.
Faresay is early-stage and bootstrapped, and we'd rather tell you exactly where we stand than overstate it. Formal certification is our direction of travel — Cyber Essentials, then ISO 27001, then SOC 2 as we scale — and an independent penetration test is planned around launch. Where a control is inherited from a certified provider (Vercel, Neon, Stripe, Clerk), we can supply theirSOC 2 or ISO 27001 evidence under NDA.
We'll complete your security questionnaire and share our DPA, sub-processor list and sub-processor certifications under NDA.
security@faresay.com