Skip to content

Trust center

How Falnor handles production work

Deployment boundary, data flow, retention, subprocessors, secrets, human approvals, model providers, incident response, and the DPA path - written plainly, without implying certifications we have not earned.

Overview

Falnor is an implementation studio. For insurance ops and healthcare RCM workflows, production work runs in your cloud and systems of record. This page covers how we draw that boundary, what the marketing site collects, and how security reviews usually proceed.

This page summarizes:

  • Where workflow data runs (your cloud vs Falnor marketing systems)
  • How data moves during an engagement
  • Retention defaults and what you control
  • Subprocessors for the marketing site and for delivery
  • Secrets, human gates, model providers, and incident response
  • How to request a DPA - and our honest certification status

Deployment boundary

Client workflow agents, connectors, eval harnesses, and production records are deployed into your environment (your cloud account, VPC, or approved tenant) under the engagement SOW. Falnor does not operate a multi-tenant SaaS that holds your claims, denials, or ERP postings as the system of record.

falnor.io (marketing, contact, booking, blog) is a separate surface. It does not receive production workflow payloads from client systems.

Data flow

Typical engagement data flow:

  1. Discovery and scoping use contact / calendar data only (name, email, workflow context you share).
  2. Build and eval work uses historical cases and system access you grant in your environment - least privilege, time-bounded where possible.
  3. Runtime actions write to your systems of record (claims, RCM, ERP, CRM, ticketing) with your audit trail.
  4. The production record (criteria, eval results, economics) is committed to your repo or object store - portable if you leave.

Retention

Marketing-site contact and booking records are retained only as long as needed to respond and operate the business relationship, then deleted or anonymized per our privacy policy.

Engagement data retention follows your SOW and your cloud policies. We do not keep a parallel copy of your production queues on Falnor infrastructure after the engagement ends, except artifacts you explicitly ask us to hold (for example, a handover pack you requested).

Subprocessors

Subprocessors for the marketing site and internal ops (not your production systems of record):

Site hosting & edge

Cloudflare (or equivalent) for falnor.io hosting, DNS, and edge delivery.

Product analytics

PostHog for anonymized or pseudonymized site analytics - configurable and documented in privacy policy.

Transactional email

Email provider for contact acknowledgements and operational mail (no client workflow payloads).

Discovery scheduling

Cal.com (or equivalent) for booking discovery calls - name, email, and meeting preferences only.

Internal ops

Internal CRM / project tools for pipeline and delivery coordination - not a store for your production systems of record.

Engagement-specific processors (model APIs, observability, identity) are chosen with you and documented in the production record collision map.

Secrets

API keys, service principals, and connection secrets live in your secret store or approved vault. Falnor engineers use time-bounded access; we do not embed long-lived client secrets in Falnor-owned repos or chat logs as policy.

Human approvals

Irreversible or high-risk actions (high-dollar posts, clinical flags, irreversible writes) require a named human gate. Approval rules are written into acceptance criteria before go-live and tested in the eval set - not left as a slide-deck promise.

Model-provider handling

We harden workflows on the agent pilots and copilots you already bought - rather than forcing a rip-and-replace. Model routing, fallbacks, and eval-on-upgrade gates are documented in the production record.

Prompt and case data sent to a model provider follows your contract with that provider (ZDR, regional endpoints, logging settings). We configure to your policy; we do not override it for convenience.

Incident response

For live workflows under Operate, material incidents get a written explanation on the agreed SLA (often within 24 hours for severity that affects production queues). Rollback paths are rehearsed before go-live. Marketing-site incidents (availability, form abuse) are handled separately and do not imply access to your production data.

DPA path

Need a Data Processing Agreement, security questionnaire, or vendor risk packet? Email support@falnor.io with your legal entity, jurisdictions, and whether the request is for the marketing site, an upcoming engagement, or both. We respond within one business day with the right packet or a scheduling link for security review.

SOC 2 and HIPAA status

Honest status - no certification claimed on this page.

  • We do not claim SOC 2 Type I or Type II certification today.
  • We do not claim HIPAA certification or BAA coverage by default on the marketing site.
  • SOC 2 and HIPAA-aligned controls are in progress for delivery engagements; status is shared on request during security review.
  • Engagement BAAs, DPAs, and control questionnaires are handled under contract - not implied by this page.