Skip to content
Company · Data and security

How we handle data.

Two kinds of data, handled separately: this page states how, plainly enough to attach to a security questionnaire.

Two data planes
Delivery datayour tenantLead dataeurope-west2

The two data planes

Every claim on this page names which of the two it covers.

Fig. 01 · The two data planes
Delivery data
What it is

Your documents and systems: everything the workflow reads and writes during an engagement.

Where it lives

Stays in your tenant, under your keys. Never copied to ours.

Lead data
What it is

What you give us when you book a review or write to us: name, email, company, and your note.

Where it lives

Stored by us in europe-west2. Used only to respond.

Delivery data is yours and stays with you; lead data is the one thing we store.

What we collect when you contact us

How in-tenant delivery works

In your tenant means built in your cloud, under your keys. The system runs in your cloud project, model calls go to your provider under your agreement, and our access is granted by you, time-bound, and revocable on the day you choose. Nothing persists outside your tenant: no copies of your documents on our side, no shadow database.

How we work, exactly

Fig. 02 · In-tenant delivery
Your tenantYour documentsand systemsThe workflowYour providerkeysModel APIunder your agreementTheFrontierForgetime-bound, revocable access

Scroll to view the full schematic

We work inside the boundary; nothing persists on our side of it.

Model training

Model calls run under your provider agreement; the major providers' API terms exclude API-submitted data from training by default; we never add your data to a training set.

Check it against the providers themselves: Anthropic's commercial terms (opens in a new tab) state that Anthropic may not train models on customer content from the services, and OpenAI's data-controls documentation (opens in a new tab) states that data sent to the OpenAI API is not used to train or improve its models unless you explicitly opt in. Both read 18 August 2026; your own agreement governs, so read it.

Encryption and access

Lead data is encrypted with provider-default AES-256 at rest and TLS 1.2 or higher in transit. Access inside the practice is least-privilege, with MFA on our accounts. Delivery data sits behind your own controls, in your tenant; we work inside them, not around them.

Retention and deletion

Lead data is kept while we work with you to answer, then deleted. Ask us to delete it sooner and we delete it from our systems; subprocessor backups expire on their own published cycles. Delivery data is not retained at all: whatever lives in your tenant is yours, and none of it lives anywhere else.

Fig. 03 · Lead-data lifecycle
deleted sooner on requestCollectedRetainedonly as long as neededDeletednotify those affected within 72 hours

Scroll to view the full schematic

Lead data follows one lifecycle: collected, kept while we answer you, then deleted; sooner on request, and any incident is disclosed to those affected.

Subprocessors, named

Every subprocessor is named here, with what it sees.

Fig. 04 · Subprocessors
Google Cloud
What it sees

Hosting in europe-west2; serves this site and stores lead data.

Data plane

Lead data

Cal.com
What it sees

Booking; what you enter when you book a workflow review.

Data plane

Lead data

Plausible
What it sees

Cookieless analytics; aggregate page views and three named conversion events, no personal identifiers.

Data plane

Neither; aggregate only

Each subprocessor, what it sees, and which data plane it touches.

This list is updated whenever it changes.

NDA and DPA

We sign your NDA and your DPA before delivery work begins, and we work under your data-transfer terms.

Incidents

If an incident affects lead data, we notify the people affected within 72 hours, with what we know and what we are doing. This is a voluntary commitment to you, distinct from the authority-notification duty data-protection law imposes. The human contact for incidents is admin@thefrontierforge.com.

Certifications, honestly

We do not hold SOC 2 today. What we do instead is on this page: two data planes kept separate, delivery in your tenant, named subprocessors, and commitments in writing. The delivery model is the point: your delivery data stays in your tenant, so its safety does not rest on our certifications. If we take one on, the date appears here when it is set, not before.

Anything this page does not answer is a fair question for the workflow review.