Data Classification Policy
Policy describing how Frontal classifies and handles data based on sensitivity.
Last updated 2026幎6æ11æ¥
This Data Classification Policy describes how Frontal Labs, Inc. ("Frontal," "we," "us," or "our") classifies data processed within the Services and the handling requirements applicable to each classification level. This policy supplements our Data Protection Policy and Data Encryption Policy. Capitalized terms not defined here have the meanings given in the Terms of Service.
1. DATA CLASSIFICATION LEVELS
Frontal classifies data into four tiers:
1.1 Public
Data that is intended for public disclosure.
Examples: Documentation, marketing materials, public website content, open-source code, public API specifications.
Handling Requirements:
- No access restrictions.
- No encryption requirements beyond TLS for data in transit to maintain integrity.
- Approved for public distribution.
1.2 Internal
Data that is not intended for public disclosure but whose unauthorized disclosure would have limited impact on Frontal, Customers, or users.
Examples: Internal documentation, team communications, operational runbooks, non-sensitive business information, aggregate usage statistics, de-identified analytics.
Handling Requirements:
- Access limited to Frontal personnel and authorized Subprocessors with a business need.
- Encryption at rest using AES-256 or equivalent.
- Encryption in transit using TLS 1.2 or higher.
- Access logging for systems storing significant volumes of Internal data.
1.3 Confidential
Data whose unauthorized disclosure, alteration, or destruction could cause significant harm to Frontal, Customers, or users.
Examples: Account Data (excluding authentication credentials), billing information (excluding full payment card numbers), Customer configuration metadata, support communications, Customer usage data that identifies specific Customers, contractual documents, business strategy documents, and employee personnel information.
Handling Requirements:
- Strict access controls with principle of least privilege.
- Multi-factor authentication required for access.
- Encryption at rest using AES-256.
- Encryption in transit using TLS 1.2 or higher.
- Access logging with automated alerting for anomalous access.
- Audit trails maintained.
- Transmission via secure channels only.
- Data minimization: collect and retain only what is needed.
1.4 Restricted
Data whose unauthorized disclosure, alteration, or destruction could cause severe or catastrophic harm to Frontal, Customers, or users. Restricted data is subject to the most stringent controls.
Examples: Account authentication credentials (passwords, API Keys, tokens), encryption keys, Customer Data (as defined in the Terms of Service, including prompts, completions, fine-tuning datasets, stored files, database contents, and vector embeddings), payment card numbers, government-issued identification numbers, and any data a Customer designates as sensitive or restricted.
Handling Requirements:
- All Confidential-level requirements, plus:
- Encryption at rest using AES-256 with customer-managed keys where offered.
- Access restricted to specifically authorized personnel and automated systems with a documented business need.
- All access logged, monitored, and subject to regular review.
- Just-in-time access where technically implemented.
- Secure key management in accordance with our Data Encryption Policy.
- No use in non-production environments without equivalent controls and de-identification.
- Physical access to infrastructure processing Restricted data is controlled and monitored.
2. CUSTOMER DATA CLASSIFICATION
2.1 All Customer Data is classified as Restricted by default.
2.2 Customers are responsible for classifying their own data and for not submitting data categories to the Services that exceed the security controls we implement. Unless you have a separate written agreement with us for HIPAA, PCI DSS, or similar regulated data, you must not submit the following categories of data to the Services:
- Protected Health Information (PHI) subject to HIPAA.
- Payment card primary account numbers (PANs) outside of our designated payment processing interfaces.
- Government-classified information.
- Data subject to International Traffic in Arms Regulations (ITAR).
- Data regulated by the U.S. Atomic Energy Act.
- Special categories of personal data under GDPR (Article 9) unless appropriate safeguards are in place and agreed in writing.
3. DATA HANDLING BY SUBPROCESSORS
3.1 Subprocessors are assessed for their ability to meet the handling requirements applicable to the data classification levels they process.
3.2 Subprocessors that process Customer Data are subject to the data protection and security requirements set forth in our Data Processing Agreement and must implement controls consistent with Restricted data handling requirements.
3.3 We maintain a Subprocessors List identifying each Subprocessor, the services they provide, the purpose of processing, and the processing location. The data classification levels applicable to each Subprocessor align with their function. Subprocessors that process Customer Data are subject to Restricted data handling requirements as described in this policy.
4. DATA CLASSIFICATION RESPONSIBILITIES
4.1 Frontal Responsibilities:
- Classify data under our control according to this policy.
- Implement and maintain controls commensurate with each classification level.
- Train personnel on data handling requirements.
- Review and update classification assignments periodically.
- Monitor for and respond to potential data handling violations.
4.2 Customer Responsibilities:
- Understand the data classification levels and handling requirements described in this policy.
- Classify Customer Data and configure Services appropriately.
- Not submit prohibited data categories unless agreed in writing.
- Implement appropriate controls on Customer-managed systems and applications that interact with the Services.
5. DATA DISPOSAL
Disposal of data at each classification level is governed by our Data Disposal Policy. Restricted and Confidential data requires cryptographic erasure or physical destruction of storage media in accordance with NIST SP 800-88 guidelines.
6. CONTACT
Frontal Labs, Inc. Attn: Data Protection 131 Continental Drive, STE 305 Newark, DE 19713 United States of America Email: dpo@frontal.dev