Foliostone holds wealth data: amounts, ownership structures, deeds, identities. This page describes the controls in place, how they are verified, and — separately — what is committed but not yet delivered. A control that rests on manual discipline alone is listed as such, not presented as operating.
Chapters: end-to-end encryption · the second lock (two-factor sign-in) · audit trail.
Film in English.
Access to production data is granted by role, for an established need, and removed on a change of function or on departure.
Every client lives in an isolated workspace. All data is tied to a workspace identifier, checked server-side on every request.
Authorisation, isolation and secret invariants block a release. An automated control does not slacken under workload.
What is not yet in place is named, dated and owned — under Programme status, not buried in careful wording.
Isolation does not rest on developer vigilance. Every data access goes through a layer that requires a workspace identifier and refuses any unclassified model: a new table cannot reach production without isolation. Authorisation fails closed — a caller whose role cannot be resolved is rejected, never handled by default.
Aggregated financial data is never written to technical logs. Operational traces are stripped of any account identifier before being sent to the monitoring service.
The revocation is carried through to the aggregator and its answer recorded. A refusal is traced and replayed — never treated as a success because the local record disappeared.
Private storage, public access never enabled, bucket posture re-checked by a scheduled task. Every read goes through a short-lived signed URL, bound to the workspace.
CSV / JSON / PDF export on verified request, deletion within 30 days. The ten-year accounting retention can survive an erasure request: the exemption is then flagged to the client.
Two shortcuts cover the real situations: presenting a file over video, or taking a screenshot for support. Masking is applied to the whole document, not to the component you remember to protect.
Privacy mode — amounts, percentages, IBANs and identifiers hidden.
Anonymisation — entities become “Entity A”, proper names become initials.
Confusing the two is the mistake this page is written to avoid. Every committed item carries a due date and an owner.
Not planned, and owned as such: SAML SSO and an enterprise IAM layer. At our size the honest equivalent is a single identity provider with enforced MFA — that is the direction we have taken.
Reports acknowledged within 48 working hours. Every incident results in a written account and, if the cause is systemic, in an automated control that would have caught it. Notification to the FDPIC, to the competent European authorities where applicable, and to the people concerned within FADP and GDPR deadlines when the threshold is met.
Isolated client workspaces, OCR import, white-label reports and in-meeting simulators.
See the Professionals page →Individuals & familiesConsolidated multi-entity view, simulated tax and estate planning, scenarios compared.
See the Individuals page →