Skip to content

Security

Your knowledge, handled with care

Frond reads some of the most sensitive material a company has. That access is read-only, permission-aware, encrypted, and never used to train shared models. Here is how we treat it.

How your data is handled

The guarantees

Encrypted, in transit and at rest

All data is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. Backups use the same standard.

Never used to train shared models

Your knowledge answers your team's questions only. It is never used to train models shared with anyone else. Read-only by default.

Permission-aware by design

Frond respects the access you already set in each source. A person only ever gets answers from documents they are allowed to see.

Model routing you can reason about

Frond routes across providers behind one interface. On Business you can route to open models you host, so sensitive knowledge stays in your perimeter.

Retention and deletion controls

Set how long data is kept, and delete a source or your whole workspace on request. Removing a source removes it from answers.

Access controls for teams

Roles and workspace access on every plan. SSO, SCIM, and an audit log on Business, for the controls procurement asks for.

Compliance

Certifications and controls

SOC 2 Type IICertified, with the current report available under NDA.
GDPRA data processing addendum is available on request.
Data residencyUS regions by default, with EU residency available on Business.
SubprocessorsA current list is maintained and updated when it changes.
Responsible disclosure

Found something? Tell us.

If you believe you have found a security issue, please report it to our team so we can fix it quickly. We investigate every report and will keep you updated. Please give us a reasonable window to resolve an issue before any public disclosure.

security@getfrondai.com

Security questions before you connect?

Talk to us about your review, permissions, and hosting. We will get you the answers and the paperwork.