Updates from the CEO · Read Albert Roberson’s latest update →

Legal

Security Notice

How we protect the information you trust us with, particularly the investigation files, which are among the most sensitive records there are.

Effective · May 20, 2026

We maintain administrative, technical, and physical safeguards designed to protect information from unauthorized access, alteration, disclosure, or destruction. Our controls are proportional to the sensitivity of the data, and the data we handle in investigations is as sensitive as it gets.

Access control

Access to client and engagement data is restricted to authorized FC personnel with a need to know, granted on a least-privilege basis and reviewed regularly. Access to active investigation files is logged and audited.

Encryption

Data is encrypted in transit (TLS) and at rest. Credentials are stored using industry-standard hashing; we never store full payment card numbers, which are handled by Stripe.

Where data lives

Application data and authentication run on Supabase, in U.S. data centers; Supabase is SOC 2 Type II compliant. Active investigation files and privileged work product are held separately on FC-managed private infrastructure in U.S. data centers, storage we control directly, because the sensitivity of that material requires it.

Subprocessors

We use a small, vetted set of subprocessors, each bound by a written data processing agreement and each SOC 2 Type II audited where applicable. The current list, with the data each one handles, is in our Privacy Policy.

Segregation of sensitive records

Investigation files are segregated from general application data. They are never used to train AI systems, and they are never anonymized and republished without the engaging institution’s written consent.

Breach notification

No system is perfectly secure. If we become aware of a breach affecting personal information, we notify affected individuals and applicable regulators in accordance with applicable law, without undue delay.

Responsible disclosure

If you believe you’ve found a security vulnerability affecting Fractional Coordinator, please email security@fractionalcoordinator.com. We appreciate responsible disclosure and will acknowledge your report.

We update this notice as our practices evolve. The “Effective” date above reflects the most recent change.