The Member Data Promise
Forward 360
Forward 360 is built on a single premise: that a Member will share things with this firm that they have never shared with anyone else. Their real numbers. Their family tensions. Their doubts about where the capital should go. The questions they haven't said out loud yet.
That kind of work requires a container. This is ours.
The principle
Everything you share inside Forward 360 belongs to you. We hold it in trust. It is never sold, never monetized, never used to serve another Member's interest, and never visible to anyone inside the firm beyond what the work requires. When the relationship ends, you leave with your Arc intact and your data fully exportable.
That is not a policy position. It is the operating condition of the Co-Creator relationship.
Banks protect data because regulators require it. We go further in the places that matter to you: your ability to see your own record, to take it with you, and to have it deleted. Those are commitments most financial institutions do not make. We make them here, in writing.
How it is protected
Encrypted at rest — by design, not as a checkbox. Every sensitive field in your Notebook — financial figures, personal financial statement, family information — is encrypted at the database level using independent encryption keys. The keys are managed by AWS Key Management Service, never stored in application code, and never accessible to layers of the system that don't require them.
Each Member's data is isolated. The system enforces strict row-level separation — your information is structurally inaccessible to queries intended for another Member. This is not access control layered on top of a shared dataset. The database itself enforces the boundary.
Every access is logged. A tamper-evident audit record is created every time your data is accessed — by a person or by the system. That log is mirrored off-system and retained for seven years. If a question ever arises about who saw what and when, we can answer it precisely.
Invite-only, no exceptions. There is no public signup path. Every Member enters through a personal invitation with a time-limited, single-use credential. The front door is structurally narrow.
Infrastructure built to financial-services standards. The system runs on AWS with private network isolation — the intelligence layer cannot be reached from the public internet. Authentication uses signed tokens, and service-to-service calls are cryptographically verified and scoped to the minimum privilege the operation requires.
Designed to fail closed. If a security control cannot be verified at startup, the system does not start. Defense is not an afterthought; it is load-bearing.
Who inside the firm can see your data
Architecture protects data from outsiders. Discipline protects it from insiders. Access inside Forward 360 is role-based and scoped to the work: the people serving your relationship can see what that work requires, and no one else can. There is no firm-wide view of Member data, no browsing, no exceptions for seniority. Every internal access is captured in the same audit log described above.
What Ike knows — and doesn't
Your Ike agent is trained on your Arc: your Manifesto, your Notebook, your decisions and the reasoning behind them. That knowledge is scoped to you. It does not cross to another Member's Ike, is not used to train or improve any general model, and is not visible to the firm except when you engage us directly in a Design Session.
You can view, edit, and delete what Ike holds about you at any time from your portal. A hard delete removes your data from the active system. Audit tombstones are retained as required by law — the record that something existed, not the content of what did.
If something ever goes wrong
No firm should ask for your trust without telling you what happens if that trust is tested. If your data is ever affected by a security incident, we will tell you — directly, promptly, and in plain language: what happened, what was affected, and what we are doing about it. Not because a regulation compels us to, but because the relationship does.
Independent verification
We do not ask you to take our word for our own security. The firm is currently undergoing a SOC 2 Type II examination — an independent audit of security controls over time, conducted by an outside firm. When it is complete, this page will say so, and the result will be available to Members on request.
The honest scope
We will tell you what we can and cannot promise.
We can promise: encryption of sensitive data, structural isolation between Members, a tamper-evident audit trail, disciplined internal access, and a firm posture that treats your information as a trust — not an asset.
We will not promise: that a system built by humans contains zero risk. No firm can make that promise honestly — and you should be wary of any that does. What we can tell you is how the system is built to behave when something is uncertain: it fails closed, it logs everything, and we tell you the truth.
Your rights
- Access — view everything the firm holds about you, at any time, from your portal.
- Correction — edit your Notebook directly.
- Deletion — request full removal. Your active data is deleted; legal retention requirements govern what the audit trail keeps.
- Portability — your Arc is exportable. You designed it; it travels with you.
A person, not a policy
Questions about how your information is handled deserve an answer from the firm, not a form. Write to member@forward360.io — a person reads it, and a person replies.
This Promise describes how Forward 360 operates today. It supplements — and does not replace — the Membership Agreement and Privacy Policy, which remain the governing documents of the relationship. The Promise is versioned: if it changes in any way that affects you, you will be notified, and no change is ever retroactive to what you shared under a prior version.
Version 1.1 — August 2026