Enterprise-Grade Security

Security & Trust Center

Enterprise-grade security and compliance built into every layer of our platform. Your data is stored exclusively in the EU, encrypted at every level, and protected by certified infrastructure.

Built for GDPREU Data ResidencySOC 2 Infrastructure
EU only

Data storage

AES-256

Encryption at rest

TLS 1.3

Encryption in transit

Security Practices

Data Encryption

All data is encrypted at rest using AES-256 and in transit using TLS 1.3. Database-level encryption is managed by Supabase with automated key rotation. Deployment credentials are encrypted via Supabase Vault (AES-256-GCM) and never logged or exposed.

EU Data Residency

All customer data is stored in the EU (Frankfurt, Germany), with application processing in EU regions (Stockholm, Paris). AI features are the one exception: the platform sends organisational context — never employee personal data — to AI model providers, which may process it outside the EU under Standard Contractual Clauses.

GDPR Compliance

Built to meet GDPR requirements: Data Processing Agreement available, data export (JSON) and account deletion in Settings, cookie consent on first visit, and privacy review as part of feature development.

Infrastructure Security

Hosted on Vercel (SOC 2 Type II certified) and Supabase (SOC 2 Type II certified). PostgreSQL with Row Level Security (RLS) enforced on every table. Automated backups, point-in-time recovery, and network isolation.

Authentication & Access Control

Email/password with bcrypt hashing, Google and Microsoft OAuth. Role-based access control (RBAC) with 7 organisation roles and 4 partner roles. SAML SSO and SCIM provisioning for Enterprise customers. All permissions enforced server-side.

Immutable Audit Trail

All significant platform actions are logged in an immutable, append-only audit trail. Records can never be modified or deleted. Full traceability for compliance reviews, incident investigation, and regulatory audits (EU AI Act Article 26).

Penetration Testing

Continuous automated security scanning runs on every code change: static analysis, dependency vulnerability screening, and secret scanning. Independent third-party penetration testing is planned; findings and remediation status will be available to Enterprise customers under NDA.

Incident Response

Security incidents are triaged and investigated under defined escalation procedures. Personal-data breaches are handled per GDPR Articles 33 and 34: notification to the supervisory authority within 72 hours where required, and affected customers informed without undue delay.

How We Handle Your Data

Your data is yours. We process it only to provide the platform services you subscribed to. Here's how we protect it at every level:

AI data handling: the platform never includes employee personal data in the context it sends to AI models — only organisational scores, aggregated metrics, and structural context. What you type to the AI Consultant is processed to answer you and is never used to train AI models.

Multi-tenant isolation: Every database table enforces Row Level Security (RLS). Partner data is strictly isolated, so one partner can never access another partner's customer data. System-level data isolation is enforced at the database layer, not just the application layer.

Anonymisation: Benchmark data and playbook library content are fully anonymised before aggregation. No company names, employee names, or identifying information is retained in shared datasets.

Compliance & Certifications

GDPR

Built to meet EU General Data Protection Regulation requirements. DPA available on request.

EU AI Act

Platform designed for EU AI Act deployer obligations. Risk classification, FRIA wizard, audit trail.

SOC 2 (infrastructure)

Infrastructure partners (Vercel, Supabase) are SOC 2 Type II certified.

ISO 27001 (roadmap)

On our roadmap. Currently following ISO 27001 best practices for information security.

Responsible Disclosure

We take security vulnerabilities seriously. If you discover a security issue, please report it responsibly.

How to Report

Email security@fronterio.com with a detailed description of the vulnerability.

Please include:

  • Description of the vulnerability and its potential impact
  • Steps to reproduce the issue
  • Your contact information for follow-up
  • Any proof-of-concept code (if applicable)

Response Timeline

  • Acknowledgement within 48 hours
  • Triage and initial assessment within 5 business days
  • Regular updates on remediation progress

Safe Harbor

We will not take legal action against researchers who report vulnerabilities responsibly, act in good faith, and do not access or modify other users' data. We ask that you allow us a reasonable time to address the issue before any public disclosure.

Need more details?

We're happy to answer security questions, provide our DPA, or walk through our security practices with your team.

Fronterio ApS
2840 Holte, Denmark
Security: Enterprise-Grade Data Protection | Fronterio