Fodda Compliance Dossier — MCP Server & API Governance

Technical governance, data handling, authentication model, and assurance position prepared for InfoSec and IT procurement teams.

1. Tool Surface & Write Capability

Fixed, versioned tool catalog with no dynamic loading, code execution, or filesystem access. Read-only graph tools are separated from account-scoped write operations.

2. Data Handling & Training Use

Query text retained in internal usage ledger for billing and telemetry; result text is not retained. Zero model training on client data. Zero-retention query logging and pseudonymous identifiers available as negotiated contract options.

3. Authentication & Credential Scope

Identity delegated to Clerk (no password custody, SOC 2 Type 2 held since May 2022). Dual-layer authentication with API keys and user IDs.

4. Assurance Position & Governance

ISO/IEC 42001 and NIST AI RMF framework alignment, founder-led engineering access, verified human oversight telemetry via Slack, and direct vulnerability triage at security@fodda.ai.

5. Security Contacts

Security & vulnerability reporting: security@fodda.ai | Procurement & compliance: compliance@fodda.ai