How we handle data.
Two kinds of data, handled separately: this page states how, plainly enough to attach to a security questionnaire.
The two data planes
Every claim on this page names which of the two it covers.
| Plane | What it is | Where it lives |
|---|---|---|
| Delivery data | Your documents and systems: everything the workflow reads and writes during an engagement. | Stays in your tenant, under your keys. Never copied to ours. |
| Lead data | What you type into our contact form: name, email, company, and your note. | Stored by us in europe-west2. Used only to respond. |
- Delivery data
- What it is
Your documents and systems: everything the workflow reads and writes during an engagement.
- Where it lives
Stays in your tenant, under your keys. Never copied to ours.
- Lead data
- What it is
What you type into our contact form: name, email, company, and your note.
- Where it lives
Stored by us in europe-west2. Used only to respond.
Delivery data is yours and stays with you; lead data is the one thing we store.
How in-tenant delivery works
In your tenant means built in your cloud, under your keys. The system runs in your cloud project, model calls go to your provider under your agreement, and our access is granted by you, time-bound, and revocable on the day you choose. Nothing persists outside your tenant: no copies of your documents on our side, no shadow database.
Scroll to view the full schematic
We work inside the boundary; nothing persists on our side of it.
Model training
Model calls run under your provider agreement; the major providers' API terms exclude API-submitted data from training by default; we never add your data to a training set.
Encryption and access
Lead data is encrypted with provider-default AES-256 at rest and TLS 1.2 or higher in transit. Access inside the practice is least-privilege, with MFA on our accounts. Delivery data sits behind your own controls, in your tenant; we work inside them, not around them.
Retention and deletion
Lead data is kept only as long as we need it to answer you, then deleted. Ask us to delete it sooner and we do, backups included. Delivery data is not retained at all: whatever lives in your tenant is yours, and none of it lives anywhere else.
Scroll to view the full schematic
Lead data follows one lifecycle: collected, retained for a fixed window, then deleted; sooner on request, and any incident is disclosed to those affected.
Subprocessors, named
Every subprocessor is named here, with what it sees.
| Subprocessor | What it sees | Data plane |
|---|---|---|
| Google Cloud | Hosting in europe-west2; serves this site and stores lead data. | Lead data |
| Cal.com | Booking; what you enter when you book a workflow review. | Lead data |
| Plausible | Cookieless analytics; aggregate page views, no personal identifiers. | Neither; aggregate only |
- Google Cloud
- What it sees
Hosting in europe-west2; serves this site and stores lead data.
- Data plane
Lead data
- Cal.com
- What it sees
Booking; what you enter when you book a workflow review.
- Data plane
Lead data
- Plausible
- What it sees
Cookieless analytics; aggregate page views, no personal identifiers.
- Data plane
Neither; aggregate only
Each subprocessor, what it sees, and which data plane it touches.
This list is updated whenever it changes.
NDA and DPA
We sign your NDA and your DPA before delivery work begins, and we work under your data-transfer terms.
Incidents
If an incident affects lead data, we notify the people affected within 72 hours, with what we know and what we are doing. This is a voluntary commitment to you, distinct from the authority-notification duty data-protection law imposes. The human contact for incidents is admin@thefrontierforge.com.
Certifications, honestly
We do not hold SOC 2 today. What we do instead is on this page: two data planes kept separate, delivery in your tenant, named subprocessors, and commitments in writing. The delivery model is the point: your data stays in your tenant, so its safety does not rest on our certifications. If we take one on, the date appears here when it is set, not before.
Anything this page does not answer is a fair question for the workflow review.
Start with the workflow review; if the fit is wrong, we say so.
- Book a workflow review
- Commission a Production Readiness Assessment
- Commission the build