Security at Formuley
We protect formula IP, supplier data, account data, and AI workflows with encryption, access controls, managed infrastructure, and clear customer data rights.
At a glance
Formula IP, supplier specs, cost data, documents, account access, billing flows, support activity, and customer exports.
Encryption, role-based permissions, vendor-managed infrastructure, and logged internal access.
Export data, request deletion, manage marketing consent, and contact security or privacy directly.
TLS + at rest
Encryption
Routine
Backups
US Region
Hosting
Role-based
Access
Formula IP Protection
Most teams do not need customer-operated on-prem to protect proprietary formulas. Formuley starts with privacy-safe product controls, then scopes dedicated infrastructure only when an enterprise security requirement truly needs it.
Exact percentages, supplier-specific records, SKU details, costs, margins, and launch timing are treated as restricted customer data.
Supplier-facing workflows exclude private formulas, percentages, costs, margins, customer lists, lab notes, and launch timing unless you explicitly share a specific artifact.
Sensitive formula, supplier, batch, document, and cost context is blocked from external AI by default and can be routed through private-lane or no-external-AI policies.
Secure deployment path
Enterprise customers can request stricter AI policies, no-external-AI posture, dedicated deployment, or customer-managed private cloud review by agreement.
Now
01
Security packet, supplier-safe data boundaries, metadata-only AI logging, private-lane controls, DPA review, exports, deletion, and audit posture.
Enterprise
02
Dedicated tenant or private cloud scope, private AI or AI disabled, custom security review, and annual agreement support.
Scoped beta
03
Available only for large enterprise requirements with paid implementation, a named customer IT owner, and shared operations responsibilities.
Platform controls
Formuley runs on managed hosting and data services with vendor security evidence available for procurement review. Formuley is not currently claiming its own SOC 2 certification.
Product and account data are encrypted at rest and in transit. Supported backups use encrypted storage.
Authenticated requests, tenant-private customer records, and internal access limits help prevent cross-customer data exposure.
Formuley runs on managed hosting and data services with standard physical, network, and operational safeguards.
Primary production hosting is in the United States today. EU data residency is planned for organizations that require EU-region hosting.
Role-based permissions, secure sessions, login notifications, and device sign-out controls protect account access.
Eligible paid plans use automatic encrypted backups. Backup retention windows vary by plan and restoration is not guaranteed after account deletion.
Export, correction, deletion, DPA, and verified manual privacy request workflows are available where applicable.
Enterprise security features
Large teams can scope identity, network, audit, and session controls through the Enterprise plan without turning every security feature into a separate product.
What we do not do
Your data rights
Export account, workspace, AI, and marketing data from settings. Delete active-system data, update information, withdraw separate marketing consent, or request security and fraud data through a verified manual privacy request.
Self-serve exports do not include security or fraud-prevention logs. Those are handled through verified manual privacy requests.
If you believe you found a vulnerability, email security@formuley.io. We acknowledge good-faith reports within 48 hours and work toward resolution.
Need a DPA, security questionnaire, subprocessor list, uptime documentation, US hosting posture, or available SCC/DPA paperwork? We can help without overstating what is live today.
Have security questions, procurement requirements, or customer review needs? We review security and procurement requests on business days.