Trust Center

Start your security review
View & download sensitive information
Ask for information
Search items
ControlK

Faros AI commitment to data privacy and security is embedded in every part of our business. This page outlines the high-level details for several frameworks, regulations, and certifications that apply to our company and its products.

Please contact security@faros.ai to report bugs and vulnerabilities or if you have any other specific questions or requests.

When reporting a bug or vulnerability, please provide a screen recording or another reproducible way of exploiting it. If a vulnerability proved in effect, we would compensate based on the fair market value for similar publicly disclosed vulnerabilities, e.g., on HackerOne.

Autodesk-company-logoAutodesk
Benchling-company-logoBenchling
BetterHelp-company-logoBetterHelp
Box-company-logoBox
Coursera-company-logoCoursera
Discord-company-logoDiscord
Salesforce-company-logoSalesforce
SmartBear-company-logoSmartBear
Vimeo-company-logoVimeo

Documents

SOC 2 Report
Network Diagram
Knowledge Base (FAQ)
    Faros Connectors IP addresses
    Faros API IP addresses
View more
Trust Center Updates

SOC 2 Type II and GDPR audit completion

ComplianceCopy link

Faros AI management would like to announce that Faros AI has completed our SOC2 Type II audit for the one-year period ending in July 2024. The auditors at Prescient Assurance performed the audit and found no exceptions during their review of our controls. The report includes an attestation of Faros AI's GDPR controls. A copy of this report is available via our security portal. The previous year's report was removed.

Published at N/A*

Faros AI management would like to announce that Faros AI has completed our SOC2 Type II audit for the one-year period ending in July 2023. The auditors at Prescient Assurance performed the audit and found no exceptions during their review of our controls. The report includes an attestation of Faros AI's GDPR controls. A copy of this report is available via our security portal.

Published at N/A*

API Key Expiration

GeneralCopy link

The Faros AI team added support for API Key Expiration. This feature enhances security by allowing customers to set a specific lifespan for API keys. Once the expiration date is reached, the key becomes invalid, reducing the risk of unauthorized access if the key is compromised. This feature helps ensure that API keys are only active for as long as necessary, encouraging regular key rotation and minimizing potential security vulnerabilities in applications.

Published at N/A

Pentest report (July 2024)

ComplianceCopy link

The Faros Infosec team has partnered with Blaze Inforsec to perform the annual pentest for Faros App & API. There were no critical or high findings. The report is available here.

Published at N/A

An Unauthenticated Remote Code Execution (RCE) vulnerability in OpenSSH (CVE-2024-6387)

VulnerabilitiesCopy link

The Faros Infosec team has evaluated our exposure to an Unauthenticated Remote Code Execution (RCE) vulnerability in OpenSSH, specifically the sshd process. The vulnerability (CVE-2024-6387) was disclosed on Monday, July 1, 2024.

We determined that the vulnerability affected none of our services, compute instances, or published containers.

Published at N/A

ISO 27001 Surveillance Audit Completion

ComplianceCopy link

Faros AI is pleased to announce the completion of the ISO 27001 annual surveillance audit. Maintaining ISO 27001 demonstrates our continued commitment to meeting international information security standards. The audit summary and updated certificate are available here.

Published at N/A

If you need help using this Trust Center, please contact us.

If you think you may have discovered a vulnerability, please send us a note.

Powered bySafeBase Logo