---
title: "Trust & Security - Fohrkast"
description: "How Fohrkast protects your data: EU data residency, encryption, never sells data, public sub-processor register, and honest limits of automated scanning."
canonical: "https://fohrkast.com/trust"
group: "Company"
updated: "2026-06-28"
---
# Trust and Security

Fohrkast is a cookie-consent widget and automated compliance scanner built on a foundation of honest communication about what automated tools can and cannot achieve. This page explains Fohrkast's real security posture, data handling, and the limits of its automated checks.

## What Fohrkast does

Fohrkast provides the following capabilities:

- Runs automated checks for cookie-consent signals, privacy, accessibility (WCAG 2.1 AA and EN 301 549), and company-information signals, showing what needs fixing.
- Hosts a consent banner that blocks non-essential trackers it detects until your visitor agrees, and logs the choice.
- Generates plain, versioned document templates with source citations for you to review and publish.
- Marks anything an automated scan cannot judge as incomplete, not passed.

## What Fohrkast does not claim

Fohrkast does not make the following claims about its capabilities or outcomes:

- Call your site compliant, accessible, or certified for you. That is a legal judgment, and the work and responsibility stay with you.
- Guarantee that you will pass an audit, avoid a fine, or avoid a legal claim. No tool can honestly promise that.
- Act as an accessibility overlay or widget. Fohrkast never pastes code over your site to fix accessibility automatically.
- Present automated results as a certification or as a substitute for legal advice.

## Security pillars

### Data residency

Account, consent proof, and hosted compliance documents are stored in the EU. The database, authentication, and storage run on Supabase in Frankfurt (eu-central-1), and the application is hosted on Vercel in the Frankfurt (fra1) region. The India-based operator may access this data to run and support the service, which is a transfer under Chapter V of the GDPR; see the privacy policy for the safeguards.

### Encryption

All traffic to Fohrkast is served over HTTPS/TLS. Data held in the managed database and storage is encrypted at rest by the underlying provider.

### Access control

Operational access is limited to what is needed to run and support the service. Fohrkast uses access controls, audit logs, rate limits, and error monitoring with personal-data minimisation.

## How we protect your data

### EU data residency

Account, consent proof, and hosted compliance documents are stored in the EU. The database, authentication, and storage run on Supabase in Frankfurt (eu-central-1), and the application is hosted on Vercel in the Frankfurt (fra1) region. The India-based operator may access this data to run and support the service, which is a transfer under Chapter V of the GDPR; see the privacy policy for the safeguards.

### Encryption in transit and at rest

All traffic to Fohrkast is served over HTTPS/TLS. Data held in the managed database and storage is encrypted at rest by the underlying provider.

### Your data is never sold

Fohrkast does not sell personal data and does not share it for advertising. Sub-processors are used only to run the service, under data processing agreements.

### You control your data

You can export or delete your data through the DSAR process. Consent proof logs are retained for up to 12 months and then deleted automatically unless deletion is required sooner.

### Least-privilege access and monitoring

Operational access is limited to what is needed to run and support the service. Fohrkast uses access controls, audit logs, rate limits, and error monitoring with personal-data minimisation.

### AI on minimised data

When AI drafts a document or scan summary, the legal name, contact email, address, company number, and named processors are masked before any prompt is sent and restored locally afterwards. The AI provider receives anonymised template text, not your personal data.

## Sub-processors

Fohrkast maintains a public register of the third parties that process data on its behalf, with each one's purpose and region. This is itself a GDPR good-practice signal: you can see exactly who is in the chain before you rely on Fohrkast.

See the sub-processor register for the full list.

## Certifications

Fohrkast lists only certifications it actually holds:

- GDPR data processing agreement: Available
- ISO 27001 / SOC 2: Not yet audited

## Legal references and data rights

For full detail of what Fohrkast collects, why, and your rights, see:

- Privacy policy
- Data processing addendum (available for customers acting as controllers)
- To report a security concern, email support@fohrkast.com

## Frequently asked questions

**Where is my data stored?**

Your account, consent records, and hosted documents are stored in the EU. Fohrkast uses Supabase (Frankfurt, eu-central-1) for the database and storage, and Vercel (Frankfurt, fra1) for the application.

**Can Fohrkast guarantee my site is compliant or accessible?**

No. Fohrkast is an automated scanner and consent banner, not a legal service. It cannot certify compliance or guarantee you will pass an audit or avoid a fine. Automated scans cannot judge everything; some items are marked incomplete, not passed. The responsibility for compliance and accessibility stays with you.

**How long are my consent records kept?**

Consent proof logs are retained for up to 12 months and then deleted automatically, unless deletion is required sooner or you request it through the DSAR process.

**What happens to my data if I delete my account?**

You can export or delete your data through the DSAR process. Fohrkast does not sell your data and does not share it for advertising purposes.

**Does Fohrkast use my data to train AI models?**

When Fohrkast uses AI to draft a document or summarise a scan, your personal data (legal name, contact email, address, company number, named processors) is masked before any prompt is sent to the AI provider. The AI receives only anonymised template text. The data is restored locally after the response is received.

## About Fohrkast

Fohrkast is an EU-focused compliance scanner and cookie-consent widget designed to help website owners prepare for GDPR, ePrivacy, and accessibility standards. Built with honesty about the limits of automation, Fohrkast emphasizes data residency in the EU and transparent security practices.

---

Source: https://fohrkast.com/trust
This is automated readiness information, not legal advice or a guarantee of conformance. Last reviewed 2026-06-28.
