Frontal is live.Read the announcement

Trust and security

Security follows the boundaries of the platform.

Frontal is an enterprise domain-AI platform: governed data, retrieval, model inference, agent orchestration, and product APIs run across a regional, multi-service architecture. Our security documentation distinguishes current evidence from work that is still planned or migrating.

Security across the platform

These documented principles describe where security boundaries belong across Frontal's architecture. Some transport and service migrations remain in progress; consult the Trust Center for maintained security and compliance evidence.

Architecture and tenant isolation

Frontal is a domain-AI platform built from services that own their implementations, contracts, and infrastructure. Tenant and environment context are expected to travel with requests across the platform.

Data protection and residency

Production runs in regional cells, currently documented in the US (iad) and EU (fra). The architecture intends to keep failover within jurisdiction. Review the Trust Center for current data handling and residency evidence.

Identity and access

The governance model covers roles and attributes for people, scoped keys for applications, policy decisions, approvals, and append-only audit records for security-relevant actions.

Infrastructure and workloads

Cloudflare Workers provide the edge layer, with regional API routing to domain-owned services and databases on Fly.io. Frontend applications are deployed on Vercel.

AI, models, and agent execution

The platform architecture separates inference, agent orchestration, and product APIs. Context and tool permissions are intended to be enforced where data is accessed or actions are performed; migration work remains in progress.

Monitoring and incident response

Observability is OTLP-first across logs, metrics, and traces. Tenant identity should come from authenticated edge context, and browser clients should not receive observability credentials.

Related security resources

Explore the published policies, technical guidance, and customer support articles behind these platform controls.

Review security and compliance evidence.

The Trust Center is the maintained source for current security and compliance documentation and available audit materials.

We use cookie-free analytics by default. Accept cookies to help us track your visits across sessions for more accurate data.