Security

Trust isn't a banner. It's how we operate.

Fronts.ai stores your business: bookings, customers, payments, content. This page documents how that data is encrypted, who can touch it, what we do not do with it, and how to get it out if you ever decide to leave.

Six security pillars

Encryption in transit and at rest

All traffic is served over HTTPS with TLS 1.2+. Application data and customer media live in encrypted storage at rest in our cloud provider, with managed keys.

Payments handled by Stripe

We never see or store raw card numbers. Card data is tokenized by Stripe (a PCI DSS Level 1 service provider) and your store charges run on top of that.

Your content is yours

We do not sell customer data, and content you create on Fronts.ai is not used to train third-party AI models. AI generation runs on your prompts and settings only.

Hardened infrastructure

Servers run in vetted cloud regions with isolated environments per service, automated dependency scanning, and least-privilege IAM for every internal tool.

Strong authentication

Passwords are hashed with industry-standard algorithms. Session tokens are short-lived and scoped. Internal admin access requires SSO and is reviewed quarterly.

Backups & recovery

Production databases are backed up on rolling schedules with point-in-time recovery, and we run periodic restore drills so the procedure is real, not theoretical.

Compliance & roadmap

We document the controls we have today instead of overstating future ones. Items marked roadmap are explicit commitments, not marketing.

  • GDPR-aligned data processing for EU/UK customers (DPA available on request)
  • Stripe-managed PCI DSS scope for all card payments
  • SOC 2 Type I roadmap targeted for 2027 (request status update from sales)
  • Customer data residency: primary region North America (Canada/US)
  • Sub-processor list available on request

Data practices, in plain English

What we collect
Account data (email, name, business details), site content you publish, billing metadata via Stripe, and product analytics events tied to your account.
How long we keep it
Active accounts: as long as your subscription is active. Cancelled accounts: site content retained 30 days, then deleted unless legally required.
Who can access it
You and the team members you invite. ProcessUs engineers access production only with logged, time-bound credentials, for explicit support cases.
How to export or delete
Export site content from Settings → Export. To delete an account and all associated data, email [email protected] with the request from your account email.

Found a vulnerability?

Email [email protected] with a description and reproduction steps. We acknowledge reports within two business days and credit researchers in our security changelog (with permission).