Trust centre
Security and compliance at Frontline
Frontline holds board-level safety and risk data for industrial operations. This is where our controls, our subprocessors and our security documentation live.
How does Frontline keep customer data secure?
Frontline holds board-level safety and risk data, so it runs on cloud hosting in the region you choose - Australia or the EU - with data encrypted in transit and at rest, single sign-on with enforced multi-factor authentication, and per-tenant isolation enforced by a test gate rather than by convention. There are 47 controls in place across infrastructure, product, process, privacy and the organisation itself, and SOC 2 Type II and ISO/IEC 27001 reports are available on request.
- Hosted in Australia or the EU, chosen per account
- TLS 1.2+ in transit, AES-256 at rest
- SSO and SCIM over SAML 2.0, with MFA enforced
- Per-tenant isolation enforced by an automated test gate
Compliance
Frameworks we hold ourselves to
- SOC 2 Type IIReport available on request
- ISO/IEC 27001Report available on request
- GDPRDPA available
- Data residencyAustralia and EU
Controls
47 controls, in place today
Every control below is implemented, not planned. Evidence for any of them comes with the SOC 2 report.
Infrastructure security13
- Unique account authentication enforced
- Multi-factor authentication required
- SSO and SCIM provisioning (SAML 2.0)
- Role and site-level access controls
- Data encrypted in transit (TLS 1.2+)
- Data encrypted at rest (AES-256)
- Production database not publicly reachable
- Encryption key access restricted
- Secrets managed with libsodium
- Access provisioned on least privilege
- Access revoked on exit
- Access reviews conducted
- Object storage private, with time-limited URLs
Product security9
- Per-tenant isolation enforced by test gate
- Server-side authorisation on every request
- Input validated at the API boundary
- Automated quality gate on every change
- Protected main branch, no bypass
- Immutable pull-request and deploy audit trail
- Staging canary before production
- Vulnerability remediation SLAs defined
- Independent penetration testing
Internal security procedures9
- Security incident response plan established
- Incident reporting process established
- Business continuity plan established
- Disaster recovery plan established
- Automated backups
- Log management and review
- Risk assessment conducted
- Vendor security reviews
- Cyber risk assessments conducted
Data and privacy8
- Data classification policy established
- Data retention schedule established
- Customer data deleted on request
- Privacy management program (AICPA)
- Data processing agreements with subprocessors
- Personal data is never sold
- Customer retains ownership of their data
- AI inputs not used to train third-party models
Organisational security8
- Code of conduct established
- Security policies reviewed
- Policy training and acknowledgement program
- Password policy enforced, 12 characters or more
- Workstation encryption required
- Removable-media and BYOD policy
- Asset inventory maintained
- Endpoint protection deployed
Subprocessors
Subprocessors
The full list, what each one is for, and where it holds data. Every one is bound by a data processing agreement.
| Subprocessor | Purpose | Location | Data it receives |
|---|---|---|---|
| Amazon Web Services | Object and file storage (S3) | Australia or EU | Uploaded files, attachments, photos and documents. |
| Fly.io | Cloud hosting and production database | Australia or EU | All customer records, including safety, incident, risk and account data. |
| Clerk | Authentication and identity | United States | User identities, email addresses and authentication events. |
| OpenAI | AI features | United States | Customer content submitted to AI features. |
| OpenRouter | AI model routing | United States | Customer content submitted to AI features. |
| Sentry | Error and performance monitoring | United States | No customer personal data. Error and performance telemetry only. |
| Resend | Transactional email | United States | Recipient addresses and message content for notifications. |
- Amazon Web Services
- Encrypted, private S3 buckets. Files are served only through short-lived, signed URLs.
- Fly.io
- Hosts the Frontline application and primary Postgres database on a private network not reachable from the public internet.
- Clerk
- Manages sign-in, SSO and enforced multi-factor authentication. Frontline stores no passwords.
- OpenAI
- Processes prompts for assistant and drafting features. Inputs are not used to train OpenAI's models, and use is bound by a data processing agreement.
- OpenRouter
- Routes AI requests to underlying model providers under contractual no-training terms.
- Sentry
- Application monitoring. Personal data is scrubbed and redacted before events are sent, so Sentry does not receive customer personal information.
- Resend
- Delivers transactional email such as alerts, reminders and action items.
Questions security reviews ask
Where is our data stored?
In Australia or the EU, whichever region you pick when your account is set up. The application and the primary Postgres database run on Fly.io in that region, and uploaded files sit in private S3 buckets in the same one.
How is one customer's data kept separate from another's?
Every org-scoped query filters on the organisation, and that isolation is enforced by a test gate rather than by convention, so a change that breaks it fails the build before it ships.
Is our content used to train AI models?
No. Content submitted to AI features is processed under contractual no-training terms with both OpenAI and the providers reached through OpenRouter, and is covered by data processing agreements.
Can we get your SOC 2 or ISO 27001 report?
Yes, on request. Use the request link on this page and say which document you need, and we will send it under NDA.
Do you support SSO and enforced MFA?
Yes. SSO and SCIM provisioning over SAML 2.0, tested against Okta and Microsoft Entra ID, with multi-factor authentication enforced on all accounts. Frontline stores no passwords itself.
What happens to our data if we leave?
You keep ownership of it throughout. On request we delete it, and the retention schedule that governs how long anything is held is a documented policy rather than a case-by-case decision.
Need something for your security review?
Tell us which document you need and we will send it under NDA, usually the same day.