Calling all FourSight Certified Facilitators: join us at our first-ever "FourSight Refresh" on Sep 17 Details here
FourSight holds assessment results about named individuals. This page sets out the controls that protect that data, the contractual commitments we make about it, and the documents you can read for yourself. It covers both foursightonline.com and the platform at app.foursightonline.com.
Issued 07 August 2026. Select any area for the technical detail.
Every control in one place, across identity, data, application, network, privacy and governance, including what is in progress and what we do not have.
foursightonline.com. Public content, published policies, and the store front. Hosted on
HubSpot.
app.foursightonline.com. The FourSight platform: assessments, thinking profiles, team
reports, and administration. This is where customer and participant data is held.
Served from a separate identity domain, so application code never handles password material.
Assessment responses, thinking-profile results, and the contact details needed to deliver them. FourSight processes results about named individuals, so privacy and data governance are treated here as first-class controls rather than an afterthought.
07 August 2026. This page is reviewed when the platform changes.
SecurityScorecard A, 97 out of 100.
Assessed from outside, without our involvement. It reflects the same view of the platform that an attacker has.
Recalculated continuously rather than at a single point in time.
None recorded in the assessment period.
An outside-in rating is not an audit. It observes what is reachable from the internet; it does not examine internal controls, policies or processes.
A managed identity service on a domain separate from the application.
Signed tokens are issued at sign-in and validated server-side on every request. Expired or altered tokens are rejected.
Enforced centrally. Administrator-issued temporary passwords expire automatically.
Supported.
Staff and platform components hold least-privilege roles rather than shared standing credentials.
Encrypted at rest with a managed key. Deletion protection is enabled.
TLS 1.2 or higher across the application, the identity domain and the API. Plaintext requests are redirected, and HSTS is set for the domain and its subdomains.
The identity store and object storage are encrypted with managed keys held in the cloud provider key service.
Amazon RDS PostgreSQL, Multi-AZ, in a private subnet with no internet-facing route.
Private object storage. Public access is denied by policy, and content is delivered only through the application.
Card data is handled by the payment provider and is never stored by FourSight.
A single content-delivery entry point. Origin infrastructure is not directly addressable from the internet.
Application and database tiers sit in private subnets governed by security groups.
Reachable only through an authorised application request. There is no internet-facing access to the data tier on any port.
Absorbed at the network edge, away from FourSight infrastructure.
Hardened. Only code from FourSight and its content network may execute, and dynamic evaluation is disabled.
X-Frame-Options: DENY. The application cannot be embedded in another site.
Secure, HttpOnly and SameSite are set on session, identity and
anti-forgery cookies.
nosniff. Declared content types are taken literally.
Browsing context and resources are isolated to same-origin.
Console sign-ins and API calls are recorded continuously across the account, supporting reconstruction of who did what, and when.
Operational and security thresholds are alarmed, so problems are raised actively rather than waiting on a dashboard.
Every sign-in attempt is captured with its outcome.
Read the Privacy Policy. What we will and will not do with your data.
Cookie Policy. What we set, and why.
Participants who took an assessment from a link are covered by the same Privacy Policy as customers.
Requests to access, correct or delete personal data are handled under the Privacy Policy and, for customers, the Data Processing Agreement.
Legal and privacy hub, organised by relationship: everyone, participants, and customers.
Read the Data Processing Agreement. How we process customer data as a processor.
The DPA incorporates the EU Standard Contractual Clauses, a recognised safeguard for personal-data transfers from the EU to the US.
A sample Services Framework Agreement is available through the legal hub for customers who need one.
Notification obligations to customers are set out in the DPA.
Cloud infrastructure hosting.
Authentication services.
Transactional email delivery.
Help-desk software. Not used to deliver the service, but listed because support conversations can contain personal data.
Customers can subscribe on the sub-processor page to be notified when a new sub-processor is engaged.
SecurityScorecard A, 97 out of 100, recalculated continuously by a third party with no involvement from us.
Our Data Processing Agreement places binding obligations on how we process customer data, and incorporates the EU Standard Contractual Clauses for transfers out of the EU.
Our Privacy Policy and DPA are written to support customers in meeting their obligations under the GDPR and US state privacy law.
Every sub-processor that touches customer data is named publicly, with a subscription for change notifications.
Published in full in the appendix to this report, including configuration detail that most vendors do not disclose.
FourSight does not currently hold a SOC 2 Type II attestation or ISO 27001 certification. We support customer security reviews directly: we complete SIG, CAIQ and buyer-specific questionnaires on request, and this report is designed to answer most of one before it is sent.
Our platform is used by large enterprises whose own procurement and information-security teams have assessed us. References are available through your account contact.
FourSight Ethical Use. How the thinking profile may and may not be used.
FourSight results describe problem-solving preference, not ability or worth. They are not a selection, promotion or performance-ranking instrument.
Content Moderation at FourSight. Hate speech, violence and discrimination are not permitted on the platform, and there is a route to report violations.
Contact FourSight. Security reports are routed to the platform team.
We welcome reports from security researchers and from customers. Send findings through the contact route above.
Obligations to customers are set out in the Data Processing Agreement.
max-age=15552000; includeSubDomains. Browsers refuse plaintext for the domain and its
subdomains
DENY. The application cannot be embedded in another site
nosniff. Declared content types are taken literally
no-referrer. No URL data leaves with outbound requests
same-origin. The browsing context is isolated
same-origin. Resources are not readable cross-origin
off
noopen
none
0. Deliberately disabled, superseded by Content Security Policy
default-src 'self' object-src 'none' base-uri 'self'
frame-ancestors 'none' script-src-attr 'none'
upgrade-insecure-requests
script-src, style-src, connect-src, img-src, font-src, form-action
unsafe-eval and all plaintext HTTP sources. Resources restricted to the application and
its CDN.
Secure HttpOnly SameSite
Session cookies, identity cookies, and anti-forgery tokens alike.
Session hijacking, cookie theft through cross-site scripting, and cross-site request forgery.
CVE-2025-23419, CVE-2024-7347, CVE-2023-44487. Each was checked against the running platform rather than accepted from scanner output.
Request inspection, TLS handshake analysis, HTTP/2 verification, response header analysis, and web server version verification.
Content Security Policy, HTTPS, HSTS, X-Frame-Options, X-Content-Type-Options, cloud provider findings, object storage findings, DKIM, DMARC
False positives documented alongside the compensating controls that make them non-exploitable.
Contact us today to learn more about our offer and how FourSight can help your teams work better together.
If you'd like to learn more about FourSight before scheduling a call, click below to learn about our platform and the science behind FourSight.