Security

Security and compliance, built into how Frontbase operates

We maintain the highest standards of security and compliance to protect your business data and ensure regulatory adherence across industries.

Certifications and compliance

Industry-standard certifications and compliance frameworks we adhere to.

SOC 2 Type II

Certified

Annual security audits covering availability, processing integrity, confidentiality, and privacy

Independent third-party audits verify our security controls and procedures

HIPAA Compliant

Compliant

Healthcare data protection standards for medical practices and healthcare providers

Business Associate Agreements available for healthcare customers

GDPR Ready

Compliant

European data protection regulation compliance for EU customers and data subjects

Data processing agreements and privacy controls for international operations

CCPA Compliant

Compliant

California Consumer Privacy Act compliance for California residents

Consumer rights management and data transparency controls

Security architecture

Multi-layered security controls protecting your data and operations.

End-to-End Encryption

All data encrypted in transit with TLS 1.3 and at rest with AES-256

  • TLS 1.3 for data in transit
  • AES-256 encryption at rest
  • Key rotation and management
  • Perfect Forward Secrecy

Infrastructure Security

Enterprise-grade cloud infrastructure with multiple security layers

  • AWS/GCP security controls
  • Network segmentation
  • DDoS protection
  • 24/7 monitoring

Access Controls

Strict identity and access management with least privilege principles

  • Multi-factor authentication
  • Role-based access control
  • Single sign-on (SSO)
  • Audit logging

Data Isolation

Tenant isolation and data segregation to protect customer information

  • Logical data separation
  • Encrypted data storage
  • Secure data processing
  • Clean data deletion

Data processing principles

Our commitment to responsible data handling and privacy protection.

1

Data Minimization

We collect only the minimum data necessary to provide our services effectively.

2

Purpose Limitation

Data is processed only for the specific purposes for which it was collected.

3

Storage Limitation

Data is retained only as long as necessary for business and legal requirements.

4

Accuracy Principle

We maintain accurate and up-to-date data with mechanisms for correction.

5

Transparency

Clear communication about data collection, processing, and usage practices.

6

User Control

Users have control over their data with rights to access, correct, and delete.

Audit reports and assessments

Regular third-party audits and security assessments.

SOC 2 Type II Report

Comprehensive security audit report covering our controls and procedures

Year: 2024Available

Penetration Testing

Third-party security testing of our systems and applications

Year: 2024Completed

Vulnerability Assessment

Regular vulnerability scans and security assessments

Year: 2024Ongoing

Security policies and procedures

Comprehensive policies governing our security operations.

Information Security Policy

Comprehensive security governance and risk management framework

Incident Response Plan

Detailed procedures for security incident detection, response, and recovery

Data Retention Policy

Clear guidelines for data lifecycle management and secure deletion

Vendor Security Program

Security requirements and assessments for all third-party vendors

Security questions?

Have questions about our security practices or need compliance documentation? Our security team is here to help.

Security Team

Technical security questions

security@frontbase.ai

Compliance Team

Compliance and audit documentation

compliance@frontbase.ai