Security
Last updated September 25, 2026
This page describes what's actually true today, and is explicit about certifications we don't hold yet. We'd rather this page under-claim than over-claim.
Tenant isolation
Every tenant-scoped database table is queried through one shared code path that filters by organization automatically - there is no way for application code to accidentally query across tenants, and this is enforced by an automated check in continuous integration, not just a coding convention.
Access control
- Role-based permissions (Owner, Admin, Manager, Agent, Viewer) with a defined permission catalog
- Every write by a human or the AI is recorded to an audit log
- Session tokens are short-lived; refresh tokens are rotated on use and stored as hashes, never in plain text
- Two-step sign-in for your own team, which an owner can require for everybody in the account
- Sign out of every device at once, from your profile, which ends every session including the one you are using
- Members can be scoped to particular locations, and see only those
- Every authenticated route is checked by a test that walks the whole API: a new endpoint that forgets to ask who is calling fails the build rather than shipping
FrontivaTech staff access
Our own team works in a separate admin with its own accounts. Your team's logins never open it, and staff logins never open your account directly.
- Every staff sign-in needs a password and a code from an authenticator app. Repeated wrong attempts lock the account for a while.
- Staff sessions end after 30 minutes without activity, and can be signed out remotely at any time.
- Each staff member has a role, and our servers check that role on every request. Sensitive actions ask for a fresh code first.
- To help with your account, a staff member starts a support session. It needs a written reason, lasts at most 60 minutes, uses the access of one member of your team rather than special powers, and can be ended at any time.
- The start and end of every support session, and every change made during one, are written to your account's audit log with the staff member identified.
- Staff actions are also recorded in our own audit log. Its entries cannot be edited or deleted by the application, and each entry is linked to the one before it so a change made behind its back can be detected.
Data protection
- Secrets and credentials are encrypted at rest
- Consent and opt-out (STOP/HELP) handling is built into the messaging layer, not bolted on
- You choose how long your conversations are kept, and the screen shows you exactly what a policy would remove before you save it. It is off unless you turn it on.
- Export everything in your account, and request its deletion, from your own settings. Deletion is scheduled rather than instant, and you can call it off.
- IP addresses on enquiries and sign-ins are shortened to their network after 90 days
- Backups run nightly and have been restored in a drill, not just written. Copies to storage outside this server are built and are switched off until the bucket exists, which we would rather say than imply.
Responsible AI
- The AI agent only answers from facts and FAQs a human has approved - no invented answers
- Deterministic guardrails run before any answer is attempted: prompt-injection detection and sensitive-domain refusal
- Every AI action is logged and reviewable
- Every reply says which of your own answers it came from, and how well the question matched, before anybody approves it
- You choose how much of a customer's history the agent may read: this message only, this conversation, or their earlier conversations as well. The widest setting is opt-in and bounded.
- A question it cannot answer from your approved knowledge is handed to a person rather than guessed at, and the customer is told
The website chat widget
- The key in your page source identifies your business and grants no access to anything. Reading a conversation needs a signed token scoped to that one conversation, so one visitor cannot read another's.
- You can restrict the key to your own web addresses
- It sets no cookie. A visitor's chat lives in their tab and ends when they close it, so the widget needs no consent banner of its own.
- A visitor is never told whether a person or the AI answered, and a draft awaiting your approval is never shown to them
If you are filling in a vendor security questionnaire
The answers are already written, with a reference per row you can quote and a plain-text version to attach to a ticket: our Trust Center. It includes the certifications we do not hold and the one backup gap we have not closed, which is the half of a questionnaire nobody volunteers.
What we don't claim
We are not SOC 2 certified, not HIPAA certified, and don't publish uptime percentages we haven't measured. If a certification matters to your business, ask us directly for current status rather than assuming from marketing copy - ours or anyone else's.
Subprocessors
Providers that process data on our behalf, and where they are. Rendered from the same list the data processing addendum uses, because this page and that one held separate copies and had already begun to disagree.
- Hostinger (Lithuania, servers in the United States) - hosting, the database, and our own email.
- Twilio (United States) - sending and receiving text messages and calls.
- Anthropic (United States) - the AI that drafts and sends replies.
- Meta Platforms (United States) - Instagram, Messenger and WhatsApp messaging, for customers who connect them.
- Stripe (United States) - card payments and invoices, once billing is switched on. Card details are entered on Stripe's own pages and never reach Frontiva.
- Google (United States) - website analytics on frontivatech.com, only for visitors who allow it. It sees no customer data from the product.
Responsible disclosure
Found a security issue? Email security@frontivatech.com. We don't have a formal bug bounty program yet; we do respond to and fix real reports.