Frontal ist live.Ankündigung lesen
Legal/Policy

Data Protection Policy

Policy describing Frontal's technical and organizational security measures for protecting Customer Data.

Last updated 11. Juni 2026

This Data Protection Policy describes the technical and organizational security measures implemented by Frontal Labs, Inc. ("Frontal," "we," "us," or "our") to protect Customer Data and to ensure the security, confidentiality, integrity, and availability of the Services. This policy is incorporated into the Terms of Service and supplements our Data Processing Agreement. Capitalized terms not defined here have the meanings given in the Terms of Service.

1. INFORMATION SECURITY PROGRAM

1.1 Frontal maintains a comprehensive written information security program based on industry standards, including ISO/IEC 27001:2022 and NIST Cybersecurity Framework. The program is reviewed and updated at least annually or upon material changes to the Services, technology, or threat landscape.

1.2 The information security program is overseen by Frontal's Security function, which reports to executive leadership. Responsibilities for security are formally defined and assigned.

1.3 Frontal's information security program is designed and implemented to align with SOC 2 Trust Services Criteria (Security, Availability, and Confidentiality). Frontal is pursuing SOC 2 certification under a phased roadmap: SOC 2 Type I within 12 months of the first enterprise contract effective date, and SOC 2 Type II plus ISO/IEC 27001:2022 within 24 months. Until certifications are obtained, Frontal provides compensating evidence including penetration test summaries, security questionnaire responses, and documented security policies. Enterprise Customers may request available audit reports and certification documentation through the security review process. See the Enterprise Terms and Conditions for the full certification roadmap.

2. ORGANIZATIONAL SECURITY

2.1 Policies and Procedures

Frontal maintains documented policies and procedures governing:

  • Information security governance.
  • Access control and identity management.
  • Asset management.
  • Incident response.
  • Business continuity and disaster recovery.
  • Vulnerability management.
  • Secure development and change management.
  • Data classification and handling.
  • Personnel security.
  • Third-party risk management.
  • Encryption and key management.
  • Network security.

2.2 Personnel Security

  • Background checks are conducted on all personnel prior to engagement, to the extent permitted by applicable law.
  • All personnel with access to Customer Data must execute confidentiality agreements.
  • Personnel receive security awareness training at onboarding and annually thereafter.
  • Personnel with access to production systems receive role-specific security training.
  • Access rights are promptly revoked upon termination of employment or engagement.
  • Access rights are reviewed at least quarterly.

2.3 Risk Management

  • Frontal conducts periodic risk assessments to identify, assess, and manage security risks.
  • Risk treatment plans are developed for identified risks exceeding risk appetite thresholds.
  • Risk assessments consider threats to confidentiality, integrity, and availability of Customer Data.

2.4 Third-Party Risk Management

  • Subprocessors and vendors undergo security review before engagement.
  • Reviews assess each vendor's security program, certifications, data handling practices, and compliance with Applicable Data Protection Law.
  • Vendors that process Customer Data are contractually obligated to implement security measures consistent with this policy.
  • Ongoing monitoring of vendor security posture is conducted for critical vendors.

3. ACCESS CONTROL

3.1 Authentication

  • Multi-factor authentication (MFA) is required for all access to production infrastructure and systems processing Customer Data.
  • Single sign-on (SSO) with MFA is used for internal corporate systems.
  • Password policies enforce complexity requirements and prohibit password reuse.
  • API access uses token-based authentication with configurable expiration.
  • Service-to-service authentication uses short-lived credentials issued by a centralized identity service.

3.2 Authorization

  • Access to systems and data is based on the principle of least privilege.
  • Role-based access controls (RBAC) are implemented.
  • Production access requires a documented business need.
  • Privileged access is reviewed at least quarterly.
  • Just-in-time (JIT) access with automatic expiration is implemented for elevated privileges where technically feasible.
  • Separation of duties is enforced between development, operations, and security functions.

3.3 Customer Access Controls

  • Customers control access to their Accounts through their own authentication and authorization mechanisms.
  • Customers may implement MFA, SSO, IP allowlisting, and session management policies for their Authorized Users.
  • API Keys are scoped to specific permissions and may be revoked at any time.
  • Enterprise Customers may integrate with their identity provider for SSO and automated provisioning.

4. NETWORK SECURITY

  • Production environments are segregated from corporate and development networks.
  • Network segmentation is implemented to limit lateral movement.
  • Firewalls and security groups enforce least-privilege network access.
  • Intrusion detection and prevention systems monitor network traffic.
  • External attack surface is minimized; only necessary services are exposed.
  • DDoS protection is implemented at the network edge.
  • Network access to production systems is logged and monitored.
  • Wireless networks within Frontal facilities are encrypted and segmented.

5. SYSTEM SECURITY

5.1 Hardening

  • Systems are hardened according to industry benchmarks (CIS Benchmarks or equivalent).
  • Only necessary services and ports are enabled.
  • Default accounts and passwords are removed or changed.
  • Unnecessary software is removed.
  • Secure configurations are applied through Infrastructure as Code and configuration management.
  • Configuration drift is detected and remediated automatically.

5.2 Vulnerability Management

  • Vulnerability scanning is performed continuously on production infrastructure.
  • Static and dynamic application security testing is integrated into the development pipeline.
  • Dependency scanning identifies known vulnerabilities in third-party libraries and container images.
  • Critical and high-severity vulnerabilities are remediated within timeframes defined in our vulnerability management program:
    • Critical: 7 days.
    • High: 30 days.
    • Medium: 90 days.
    • Low: Per risk assessment.
  • Penetration testing is conducted at least annually by an independent third party. Enterprise Customers may request a summary of findings.

5.3 Malware Protection

  • Anti-malware controls are implemented on applicable systems.
  • File uploads are scanned for malware.
  • Endpoint detection and response (EDR) is deployed on Frontal-managed endpoints.

5.4 Change Management

  • Changes to production systems follow a formal change management process.
  • Changes are tested in non-production environments before production deployment.
  • Emergency changes follow an expedited process with post-implementation review.
  • Infrastructure changes are applied through Infrastructure as Code, enabling version control, review, and rollback.

6. APPLICATION SECURITY

6.1 Secure Development Lifecycle

  • Security requirements are incorporated into the development lifecycle.
  • Threat modeling is performed for new features and significant changes.
  • Code review is required for all changes; at least one reviewer must be independent of the author.
  • Static analysis tools run on all code commits.
  • Dynamic analysis is performed on running applications.

6.2 Application Security Controls

  • The OWASP Top 10 is addressed in application design and testing.
  • Input validation and output encoding are implemented.
  • Parameterized queries and object-relational mapping prevent SQL injection.
  • Content Security Policy (CSP) headers are implemented.
  • Cross-Site Request Forgery (CSRF) protections are implemented.
  • Rate limiting and abuse detection protect APIs.
  • Session management follows OWASP best practices.

6.3 Secrets Management

  • Secrets (credentials, API Keys, tokens, certificates) are stored in a dedicated secrets management system.
  • Secrets are never stored in source code, configuration files, or environment variables.
  • Secrets are rotated automatically where supported.
  • Access to secrets is logged and audited.

7. LOGGING AND MONITORING

  • Security-relevant events are centrally logged.
  • Logs include authentication events, authorization decisions, data access, administrative actions, and configuration changes.
  • Logs are protected against tampering and unauthorized access.
  • Security Information and Event Management (SIEM) aggregates and correlates log data.
  • Automated alerts are generated for security events, including suspicious activity, policy violations, and anomaly detection.
  • Log retention is governed by the Data Retention Policy.

8. INCIDENT RESPONSE

  • Frontal maintains a documented incident response plan.
  • Incident response roles, responsibilities, and escalation paths are defined.
  • The incident response plan is documented and maintained. Tabletop exercise testing will be conducted at least annually, with the first test targeted within 12 months.
  • Incidents are classified by severity with defined response timelines.
  • Root cause analysis is conducted for significant incidents, and corrective actions are tracked.
  • Customer notification procedures are defined for incidents affecting Customer Data.
  • Post-incident reviews identify process improvements.

9. BUSINESS CONTINUITY AND DISASTER RECOVERY

  • Detailed in our Data Backup and Recovery Policy.
  • Business continuity and disaster recovery plans are documented, tested, and maintained.
  • Plans address infrastructure failure, data center loss, and key personnel unavailability.

10. PHYSICAL SECURITY

  • Production infrastructure is hosted in third-party data centers operated by our cloud infrastructure providers (AWS, GCP, Azure). Physical security is the responsibility of those providers.
  • Frontal's cloud providers maintain industry-standard physical security certifications (e.g., ISO 27001, SOC 1/2/3).
  • Frontal is a fully remote company. All personnel work remotely, and Frontal does not maintain physical office facilities. Personnel are required to secure their work devices and workspaces in accordance with Frontal's remote work security policies.

11. CUSTOMER RESPONSIBILITIES

Customers are responsible for:

  • Configuring and using the Services in a secure manner consistent with our Documentation.
  • Managing access credentials for their Authorized Users.
  • Securing systems and devices used to access the Services.
  • Reviewing and configuring security settings available within the Services.
  • Implementing appropriate security measures for applications and integrations developed using our APIs.
  • Not submitting prohibited data categories unless agreed in writing (as described in our Data Classification Policy).

12. COMPLIANCE AND CERTIFICATIONS

Frontal's information security program is designed to align with the following frameworks and standards, as applicable to the Services:

  • SOC 2 Type II (Trust Services Criteria for Security, Availability, and Confidentiality).
  • ISO/IEC 27001:2022.
  • NIST Cybersecurity Framework.
  • EU-U.S. Data Privacy Framework (EU-U.S. DPF) (certification in progress).
  • UK Extension to the EU-U.S. DPF (certification in progress).
  • Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) (certification in progress).

Current certification and attestation status, including the scope of any certifications held and those in progress, is available upon request through the enterprise security review process. Frontal's conformance with specific frameworks may vary by Service component and deployment configuration.

13. CONTACT

Frontal Labs, Inc. Attn: Security 131 Continental Drive, STE 305 Newark, DE 19713 United States of America Email: security@frontal.dev

Wir messen den Website-Traffic standardmäßig ohne Cookies. Mit Ihrer Zustimmung merken wir uns Ihren Besuch über Sitzungen hinweg, was unsere Analysen genauer macht.