SECURITY

We are committed to keeping your data safe

We build compliance software, so improving our customers’ security posture starts with our own. Freda holds the most sensitive material a company keeps, and the platform is built from the ground up to protect it.

SECURITY

We are committed to keeping your data safe

We build compliance software, so improving our customers’ security posture starts with our own. Freda holds the most sensitive material a company keeps, and the platform is built from the ground up to protect it.

SECURITY

We are committed to keeping your data safe

We build compliance software, so improving our customers’ security posture starts with our own. Freda holds the most sensitive material a company keeps, and the platform is built from the ground up to protect it.

Enterprise-grade
security and controls

Freda holds the registers a compliance function runs on. The controls around them are the ordinary platform ones, asked seriously.

Sign in the way you already do

Enterprise SAML and OIDC single sign-on, so access follows the identity provider and multi-factor rules you already run. Social and email sign-in are available where it is not.

Access granted per record, not per role

A single control, artifact or register entry can be shared with one person, a group, or everyone in the organization. Permission is a grant on the record, not a role on the account.

Agents inherit your permissions

An agent working for you carries your identity, not a service account of its own, and is checked against the same grants. It can never reach a record you could not open yourself.

Encrypted in transit and at rest

TLS 1.2 or higher wherever data crosses a network, and AES-256 at rest across every database and store. Credentials for connected systems are sealed under a key we hold ourselves.

Nothing reaches production by hand

Infrastructure is defined in code and applied through review, never by hand in a console, even in development. Nothing reaches production outside that process.

Recovery is rehearsed, not assumed

Databases back up nightly with a seven-day recovery window, and the team runs live drills that restore from those backups rather than trusting that they would work on the day.

Certifications
and frameworks

ISO 27001

Certified

ISO 42001

Certified

GDPR

Compliant

EUAI Act

Compliant

Privacy and
data protection

Where data lives

Hosted in the EU, with model inference in the EU as well.

How it is handled

Encrypted in transit with TLS 1.2 or higher and at rest with AES-256. The organization boundary is applied every time data is retrieved.

How long we keep it

Kept for the life of the contract and deleted within 30 days of termination. Backups run daily with a seven-day recovery window.

Model training

Customer data is not used to train models, and opt-out is enforced with every provider that receives it.

Questions from
your security team?

Certificates, our sub-processor list, DPA and penetration test report are available on request.

Reporting a vulnerability? Write to security@freda.com, encrypted with our PGP key if the details are sensitive.

Fingerprint 33C2 30F0 4997 F582 5ABA FBC5 94E2 8178 D5C1 3AE4

Questions from
your security team?

Certificates, our sub-processor list, DPA and penetration test report are available on request.

Reporting a vulnerability? Write to security@freda.com, encrypted with our PGP key if the details are sensitive.

Fingerprint 33C2 30F0 4997 F582 5ABA FBC5 94E2 8178 D5C1 3AE4