Security
How Fidem handles your documents
Rental application documents contain sensitive financial information. This page describes how Fidem stores, handles, and protects submitted documents — factually and without overstatement.
Document handling
Documents are uploaded directly to private, access-controlled cloud storage via a signed upload URL. Signed URLs are short-lived and scoped to the specific upload operation — they cannot be reused or shared.
Once uploaded, documents are not accessible via public links. Access to a stored document requires authentication and authorization to the associated verification workflow.
Documents are encrypted at rest using AES-256 encryption provided by the underlying AWS storage infrastructure (via Supabase Storage). Documents are encrypted in transit using TLS 1.2 or higher.
Documents are processed internally for field extraction. The raw extracted fields are used to run verification checks and produce the verification report. Raw extraction outputs are not exposed in the user interface.
Access control
All document uploads, downloads, and verification operations require an authenticated session. Unauthenticated access to documents, verification reports, or review workflows is not possible.
Each organization's data is logically isolated. Verifications created by one organization are not accessible to another.
Sessions are managed via Supabase Auth with industry-standard token handling. Session tokens are not stored in localStorage.
Storage and privacy
Documents are stored in private cloud storage buckets. No bucket has public access enabled. All storage objects require authenticated, scoped access to retrieve.
Fidem does not share submitted documents with third parties outside the document processing workflow. Extracted field data used for verification is retained as part of the evaluation record and is not exported or sold.
Documents are retained for the duration of the associated verification workflow and according to the data retention policy in our Privacy Policy. Organizations may request deletion of their verification data by contacting privacy@usefidem.com.
Data retention and deletion
Retention: Uploaded documents, extracted field data, and verification reports are retained for the duration of the active verification workflow and for up to 7 years after the application is archived, to support legal compliance and dispute resolution. Audit and activity logs are retained for a minimum of 7 years. See our Data Practices page for the full retention table.
Deletion requests: You may request deletion or redaction of your verification data, associated documents, or your entire account at any time. We will acknowledge your request within 5 business days and aim to complete it within 30 days.
Scope of deletion and redaction: Where implemented, we delete or redact raw uploaded documents, raw OCR provider fields, and direct applicant identifiers. Structured verification reports, structured facts, and immutable audit or activity log entries may be retained for legal, billing, security, and operational integrity according to our Privacy Policy and Data Practices pages. Free-text PII in retained records is redacted where our retention jobs apply. Billing records and aggregated usage logs may be retained separately for compliance purposes. External platform retention (for example observability or email providers) may require separate dashboard controls.
To request deletion: privacy@usefidem.com
Infrastructure and vendor disclosure
Fidem relies on the following infrastructure providers. We disclose these to enable informed security assessment by operators.
Supabase
Authentication, database, and object storage
Fidem uses Supabase for user authentication (Auth), verification data storage (PostgreSQL), and document storage (Storage). Supabase infrastructure runs on AWS. All data stored in Supabase is encrypted at rest by the underlying AWS infrastructure (AES-256).
Microsoft Azure
Document processing infrastructure
Document processing operations (classification and field extraction) run on Microsoft Azure. Fidem uses Azure Content Understanding for document classification and extraction. Data is processed in the East US region.
Vercel
Application hosting, delivery, and performance monitoring
The Fidem application is deployed on Vercel. Application traffic, including documents in transit, passes through Vercel-managed infrastructure over TLS. Vercel Analytics and Speed Insights receive de-identified page paths, page events, and performance telemetry; applicant upload link tokens are scrubbed before transmission.
Stripe
Payment processing and billing
Operator credit purchases are processed through Stripe Checkout. Stripe processes operator billing and payment card data; Fidem does not store payment card data. Stripe does not receive applicant documents or verification data.
Resend
Transactional email delivery
Fidem uses Resend to send transactional emails: applicant document request, reminder, and submission confirmation emails, plus operator notification, welcome, organization invite, and support emails. Resend processes recipient names, email addresses, and request or notification details for delivery purposes only. Emails never contain document contents or verification findings.
Sentry
Error tracking and monitoring
Fidem uses Sentry to track application errors and exceptions. Error reports are scrubbed of PII before transmission. Sentry receives application error context (stack traces, request metadata) — not document content or applicant personal data.
Axiom
Structured log ingestion and operational observability
When configured, Fidem sends structured application log events to Axiom for operational monitoring: event names, correlation identifiers, and error classes. Application logs are designed to exclude document contents and applicant personal information.
Google Places
Property address autocomplete
When an operator enters a property address, the typed address text is sent to the Google Places API to provide suggestions and address details. Requests are proxied through Fidem servers, and no documents or applicant data are included.
Submitted document contents are processed only by the document handling vendors described above (Supabase for storage, Azure Content Understanding for extraction). The canonical list of subprocessors and the data each receives is maintained in our Privacy Policy. This list will be updated if additional vendors are introduced.
Verification scope and data use
Fidem processes the documents an applicant submits — pay stubs, bank statements, and, where provided, employment letters and government ID — to extract specific field values (income figures, pay periods, employer details, balances, deposit activity, names, and expiry dates) for verification purposes.
Extracted data is used solely to produce the verification report for the associated workflow. It is not used to build scoring models, train AI systems, or produce tenant eligibility determinations.
Fidem does not access credit bureaus, background check providers, eviction databases, employment verification services, or any external data source. All verification is performed on submitted documents only.
Operational safeguards
All lifecycle transitions in a verification workflow — uploads, processing events, review actions, document requests — are logged and stored as immutable audit records. This provides a traceable history for every verification.
Document processing operations include retry handling with limits to prevent runaway processing. Failed processing operations surface clearly in the workspace UI for operator review and manual retry.
Server-side validation is enforced on all API boundaries. Client-side state is never trusted for authorization decisions. Access control checks are performed server-side on every request.
Security inquiries
If you have questions about Fidem's security posture, document handling, or data practices, please contact us:
- Security questions: security@usefidem.com
- Privacy and data requests: privacy@usefidem.com
For general questions, see our Privacy Policy or Terms of Service.
Reporting a vulnerability: If you believe you have found a security vulnerability in Fidem, please email security@usefidem.com with details and steps to reproduce. Please do not access, modify, or attempt to exfiltrate other users' data, and give us a reasonable opportunity to investigate and address a report before disclosing it publicly. A machine-readable version of this contact is published at /.well-known/security.txt (RFC 9116).
Note on certification: Fidem is an early-stage platform. We have not yet completed formal SOC 2 or similar audits. This page describes our actual security practices, not aspirational claims. We will update it as our security program matures.