Encryption in transit and at rest
All traffic is served over HTTPS with TLS 1.2+. Application data and customer media live in encrypted storage at rest in our cloud provider, with managed keys.
Security
Fronts.ai stores your business: bookings, customers, payments, content. This page documents how that data is encrypted, who can touch it, what we do not do with it, and how to get it out if you ever decide to leave.
All traffic is served over HTTPS with TLS 1.2+. Application data and customer media live in encrypted storage at rest in our cloud provider, with managed keys.
We never see or store raw card numbers. Card data is tokenized by Stripe (a PCI DSS Level 1 service provider) and your store charges run on top of that.
We do not sell customer data, and content you create on Fronts.ai is not used to train third-party AI models. AI generation runs on your prompts and settings only.
Servers run in vetted cloud regions with isolated environments per service, automated dependency scanning, and least-privilege IAM for every internal tool.
Passwords are hashed with industry-standard algorithms. Session tokens are short-lived and scoped. Internal admin access requires SSO and is reviewed quarterly.
Production databases are backed up on rolling schedules with point-in-time recovery, and we run periodic restore drills so the procedure is real, not theoretical.
We document the controls we have today instead of overstating future ones. Items marked roadmap are explicit commitments, not marketing.
Email [email protected] with a description and reproduction steps. We acknowledge reports within two business days and credit researchers in our security changelog (with permission).