Enterprise-grade
security and controls
Freda holds the registers a compliance function runs on. The controls around them are the ordinary platform ones, asked seriously.
Sign in the way you already do
Enterprise SAML and OIDC single sign-on, so access follows the identity provider and multi-factor rules you already run. Social and email sign-in are available where it is not.
Access granted per record, not per role
A single control, artifact or register entry can be shared with one person, a group, or everyone in the organization. Permission is a grant on the record, not a role on the account.
Agents inherit your permissions
An agent working for you carries your identity, not a service account of its own, and is checked against the same grants. It can never reach a record you could not open yourself.
Encrypted in transit and at rest
TLS 1.2 or higher wherever data crosses a network, and AES-256 at rest across every database and store. Credentials for connected systems are sealed under a key we hold ourselves.
Nothing reaches production by hand
Infrastructure is defined in code and applied through review, never by hand in a console, even in development. Nothing reaches production outside that process.
Recovery is rehearsed, not assumed
Databases back up nightly with a seven-day recovery window, and the team runs live drills that restore from those backups rather than trusting that they would work on the day.
Certifications
and frameworks
Certified
Certified
Compliant
Compliant
Privacy and
data protection
Where data lives
Hosted in the EU, with model inference in the EU as well.
How it is handled
Encrypted in transit with TLS 1.2 or higher and at rest with AES-256. The organization boundary is applied every time data is retrieved.
How long we keep it
Kept for the life of the contract and deleted within 30 days of termination. Backups run daily with a seven-day recovery window.
Model training
Customer data is not used to train models, and opt-out is enforced with every provider that receives it.