FrontierBase

Security

Certifications and third-party assessmentsInfrastructure securityClient securityData security and privacyVulnerability disclosure

Security

The security of your data and development environment is important to us. This page outlines how we approach security at FrontierBase.

For security-related questions or vulnerability reports, please contact us at:

[email protected]

Certifications and third-party assessments

We are committed to security and privacy through certifications such as SOC 2 and regular third-party security assessments. To request a copy of our report, please contact our security team.

Infrastructure security

Our service relies on the following trusted infrastructure and service providers. Each follows industry standards for data security and availability.

  • CloudflareSees code data:We use Cloudflare as a reverse proxy in front of parts of our API and website in order to improve performance and security. It provides DDoS mitigation, CDN, and security proxy.
  • FirebaseSees and stores data:We use Firebase (Google) for app backend services such as authentication, real-time data, and hosting. Data is encrypted in transit and at rest.
  • QdrantStores code data:We use Qdrant for vector search and embedding storage. Index data for RAG (retrieval-augmented generation) is managed securely.
  • Google Cloud Platform (GCP)Sees and stores code data:We host core workloads and data on Google Cloud Platform (GCP). We follow GCP's security and compliance policies.
  • OpenAISees code data:We may use OpenAI models for AI response generation. Data sent and processed is governed by OpenAI's data processing policies.
  • Google GeminiSees code data:We may use the Google Gemini API to power AI features. Request data is processed in accordance with Google's privacy and security policies.
  • DexieStores data locally:We use Dexie (IndexedDB wrapper) for client-side local storage. Data in the browser is stored only on the user's device and remains secure in offline and cache scenarios.
  • Direct VPC egressPrivate outbound access to VPC:We use Direct VPC egress when serverless workloads such as Cloud Run need private access to resources inside our VPC. This lets outbound traffic reach internal resources over a private network path without a separate connector.
  • Web Crypto APILocal processing only:For encryption, hashing, tokens, and other security-sensitive operations we use the Web Crypto API and standard cryptographic libraries. Passwords and sensitive data are processed and stored in encrypted form.

Each of the above providers has its own security and privacy policies; please refer to them as needed.

Client security

The FrontierBase web client runs in the browser and applies the following security measures.

  • All communication is encrypted over HTTPS. API and website traffic is protected by TLS.
  • Client-side data (cache, session, etc.) is stored only on the user's device via Dexie (IndexedDB). Local data that is not uploaded to servers remains only on that device.
  • Sensitive operations (tokens, authentication-related data, etc.) use the Web Crypto API and other browser-standard cryptography where possible, so they are handled securely on the client.
  • The web client communicates only with our backend and the domains of the services listed in Infrastructure security (e.g. Cloudflare, Firebase, GCP). If you use a corporate proxy or firewall, you may need to allow these domains.

Data security and privacy

We apply appropriate technical and organizational measures to the data we collect and process, including encryption in transit and at rest, access controls, and regular backups. For details on personal information handling, see our Privacy Policy.

Vulnerability disclosure

If you discover a security vulnerability in FrontierBase services, we would appreciate you notifying us before any public disclosure.

Security reports and inquiries: [email protected]

FrontierBaseCookie settings

Company

  • About us
  • Terms of Service
  • Privacy Policy

Product

  • Pricing

Resources

  • Customer support
© 2026 HADFAMILY Inc.Trust