Security & Trust Center
Enterprise-grade security and compliance built into every layer of our platform. Your data is stored exclusively in the EU, encrypted at every level, and protected by certified infrastructure.
Data storage
Encryption at rest
Encryption in transit
Security Practices
How We Handle Your Data
Your data is yours. We process it only to provide the platform services you subscribed to. Here's how we protect it at every level:
AI data handling: the platform never includes employee personal data in the context it sends to AI models — only organisational scores, aggregated metrics, and structural context. What you type to the AI Consultant is processed to answer you and is never used to train AI models.
Multi-tenant isolation: Every database table enforces Row Level Security (RLS). Partner data is strictly isolated, so one partner can never access another partner's customer data. System-level data isolation is enforced at the database layer, not just the application layer.
Anonymisation: Benchmark data and playbook library content are fully anonymised before aggregation. No company names, employee names, or identifying information is retained in shared datasets.
Compliance & Certifications
GDPR
Built to meet EU General Data Protection Regulation requirements. DPA available on request.
EU AI Act
Platform designed for EU AI Act deployer obligations. Risk classification, FRIA wizard, audit trail.
SOC 2 (infrastructure)
Infrastructure partners (Vercel, Supabase) are SOC 2 Type II certified.
ISO 27001 (roadmap)
On our roadmap. Currently following ISO 27001 best practices for information security.
Responsible Disclosure
We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.
How to Report
Email security@fronterio.com with a detailed description of the vulnerability.
Please include:
- Description of the vulnerability and its potential impact
- Steps to reproduce the issue
- Your contact information for follow-up
- Any proof-of-concept code (if applicable)
Response Timeline
- Acknowledgement within 48 hours
- Triage and initial assessment within 5 business days
- Regular updates on remediation progress
Safe Harbor
We will not take legal action against researchers who report vulnerabilities responsibly, act in good faith, and do not access or modify other users' data. We ask that you allow us a reasonable time to address the issue before any public disclosure.
Need more details?
We're happy to answer security questions, provide our DPA, or walk through our security practices with your team.