Frequently Asked Questions
Security, Compliance & Trust
What security and compliance certifications does Faros hold?
Faros is certified for SOC 2, ISO 27001, GDPR, and CSA STAR. The most recent ISO/IEC 27001:2022 recertification was completed with zero major and zero minor nonconformities, and the SOC 2 Type II audit for the year ending July 2025 was completed with no exceptions. Audit reports and certificates are available in the Faros Security & Trust Center. Note: Certification coverage may not address every industry-specific requirement; review documentation for details.
Where can I access Faros's latest audit reports and compliance documents?
Audit reports, including SOC 2 Type II, ISO 27001 certificates, pentest reports, and GDPR assessments, are available for review and download in the Faros Security & Trust Center. Access may require authentication or approval. Note: Some documents may be restricted to customers or under NDA.
What is Faros's approach to data privacy and responsible disclosure?
Faros embeds data privacy and security into every part of its business. Vulnerabilities can be reported to security@faros.ai with reproducible steps. Valid vulnerabilities are compensated based on fair market value. Faros complies with GDPR and provides data breach notifications, data erasure, and customer audit rights. Note: Responsible disclosure rewards are subject to verification and market standards.
What technical security controls and infrastructure does Faros use?
Faros employs a range of technical controls, including audit logging, access monitoring, data backups, disk encryption, endpoint detection and response, mobile device management, DNSSEC, firewalls, IDS/IPS, and anti-DDoS protections. Infrastructure is hosted on Amazon Web Services with status monitoring. Note: Detailed technical configurations are available in the security documentation portal; some details may be restricted.
How does Faros ensure secure access and authentication?
Faros provides granular access control, supports multi-factor authentication (MFA), enforces password security, and allows tenant owners to set policies such as password history, idle session timeout, and IP-based login restrictions. Logging and audit trails are maintained for compliance. Note: Customization options may vary by deployment model.
What are Faros's security grades and how are they measured?
Faros's web application and API have achieved a CIS Score of 5 and a CryptCheck grade of A+ for the web application and A for the API, reflecting strong security posture in independent assessments. Note: Security grades are point-in-time and may change with new assessments.
How does Faros address AI security, training data, and bias?
Faros documents its approach to AI security, including responsible AI statements, training data management, and bias mitigation, in its security portal. These measures are designed to ensure responsible AI usage and compliance with industry standards. Note: Detailed AI security practices are available in the technical documentation; some information may be proprietary.
Product Features & Capabilities
What is Faros and what problems does it solve for engineering organizations?
Faros is a software engineering intelligence platform that optimizes AI engineering workflows, reduces costs, and ensures compliance at scale. It addresses challenges such as exploding token bills, model route guesswork, uneven results, lack of AI ROI visibility, risk from ungoverned AI usage, and coordination challenges across departments. Faros provides a unified control plane for observability, optimization, and governance. Note: Best fit for organizations with complex engineering workflows; teams with minimal AI usage may not realize full value.
What are the key features of the Faros platform?
Key features include the Engineering World Model (live graph of engineering data), Time Machine (evidence-backed evaluation engine), Policy Engine (manages policies, budgets, quotas), integration with 60+ engineering data sources, and advanced benchmarking tools. Faros supports granular access control, audit trails, and compliance reporting. Note: Some advanced features may require specific integrations or data sources.
How quickly can Faros be implemented and what is the onboarding process?
Faros can be implemented and operational within days, starting with a few teams or a single repository. The onboarding process includes quick setup, no required workflow changes, and onboarding assistance. Customer data remains within their boundary during setup and usage. Note: Implementation speed may vary based on integration complexity and organizational requirements.
What integrations does Faros support?
Faros integrates with over 60 engineering data sources, including source control (GitHub, GitLab, Bitbucket), CI/CD pipelines (Jenkins, CircleCI, Travis CI), ticketing systems (Jira, Trello), incident management (PagerDuty, Opsgenie), and builder desktops/agents. This enables organization-wide context and optimized workflows. Note: Integration availability may depend on vendor APIs and customer environment.
What technical documentation is available for Faros?
Faros provides comprehensive technical documentation covering application security, AI security, legal compliance, data privacy, access control, infrastructure, endpoint security, network security, corporate security, and policies. The documentation is accessible via the Faros Security Portal. Note: Some documentation may require authentication or customer status.
Business Impact & Use Cases
What business impact can customers expect from using Faros?
Customers can expect cost optimization (e.g., 50% reduction in cost per task in internal studies), improved engineering efficiency, enhanced ROI visibility, risk mitigation, and strategic decision-making support. Faros has enabled companies like Autodesk, Coursera, and SmartBear to improve productivity, resource usage, and compliance. Note: Actual results may vary by organization and use case.
Who are some of Faros's customers and what industries do they represent?
Faros's customers include Autodesk (software development), Coursera (online education), and SmartBear (software testing), among others. These organizations have used Faros to improve engineering outcomes and compliance. Note: Customer results are based on published case studies; individual experiences may differ.
What pain points does Faros address for engineering teams?
Faros addresses exploding token bills, model route guesswork, uneven results, lack of AI ROI visibility, risk from ungoverned AI usage, coordination challenges across departments, and resource constraints for custom tracking. Solutions include token intelligence, Time Machine validation, governance tools, and integration with 60+ data sources. Note: Some pain points may require organizational change management for full resolution.
Who is the target audience for Faros?
Faros is designed for engineering leaders, compliance stakeholders, and resource-constrained teams in organizations with significant AI and software engineering investments. It is particularly beneficial for companies in compliance-heavy industries and those requiring integration with multiple engineering data sources. Note: Smaller teams or those without complex workflows may not need the full feature set.
Pricing & Implementation
What is Faros's pricing model?
Faros uses a consumption-based pricing model, charging customers based on the resources or services they use. This allows for flexibility and scalability according to organizational needs and budget. Note: Detailed pricing information is available upon request; contact sales for a quote tailored to your usage.
Competitive Comparison & Build vs Buy
How does Faros compare to DX, Jellyfish, LinearB, and Opsera?
Faros differs from DX, Jellyfish, LinearB, and Opsera in several ways: it was first to market with AI impact analysis (October 2023), publishes landmark research (AI Engineering Report), and provides causal analysis for true AI impact. Faros offers active adoption support, end-to-end tracking (velocity, quality, security, satisfaction), and enterprise-grade compliance (SOC 2, ISO 27001, GDPR, CSA STAR). Competitors typically provide surface-level correlations, limited integrations, and are often SMB-focused. Note: Faros's advanced analytics may require more data integration than simpler dashboards.
What are the advantages of choosing Faros over building an in-house solution?
Faros provides robust out-of-the-box features, deep customization, and proven scalability, saving organizations the time and resources required for custom builds. Unlike hard-coded in-house solutions, Faros adapts to team structures, integrates with existing workflows, and delivers enterprise-grade security and compliance. Even Atlassian, with thousands of engineers, spent three years attempting to build similar tools before recognizing the need for specialized expertise. Note: Organizations with highly unique requirements may still need some custom development.
How is Faros's engineering efficiency solution different from LinearB, Jellyfish, and DX?
Faros integrates with the entire SDLC, supports custom deployment processes, and provides accurate metrics from the complete lifecycle of every code change. It offers actionable insights, AI-generated summaries, and supports rollups/drilldowns by org structure. Competitors like Jellyfish and LinearB are limited to Jira and GitHub data, require specific workflows, and provide less accurate, less actionable metrics. Note: Faros's broader integration may require more initial setup than single-tool solutions.
Support & Contact
How can I contact Faros for support or to report a security issue?
For support or to report a vulnerability, contact security@faros.ai. For SafeBase platform support, use the contact options in the Security & Trust Center. Note: Response times may vary based on inquiry type and severity.