Security first, by design.
Connecting your data takes trust. Here's how FrontRace protects it, isolates it, and keeps you in control.
-
SOC 2 Type II
Independently audited controls, plus a CASA review and annual penetration testing.
-
Isolated by customer
Your data lives in its own dedicated, segregated database and server environment on AWS.
-
Encrypted
AES-256-GCM encryption protects your data in transit and at rest.
-
Never trains AI
Your data is never used to train external AI models, and never shared across organizations.
Your data, your rules.
-
You own it
You keep full ownership and control of everything you connect, and you can halt FrontRace's access at any time. Ask us to delete your data and we will, in line with contractual, legal, and operational requirements.
-
Read-only by default
Integrations are typically set up with read-only permissions, so FrontRace analyzes your systems without changing them. Write-back is turned on only when you ask for it and authorize it.
-
You decide what's captured
Internal-only conversations are excluded by default unless someone outside your company is involved. A user's emails, meetings, and activity are ingested only after they're assigned an approved role, and you can exclude specific people or whole departments.
-
Surfaced only where it belongs
Information appears only when it's tied to a known customer, prospect, account, contact, or opportunity. You control user permissions and who sees what.
Isolated, encrypted, tested.
-
Isolated per customer
Customer data is stored in secure AWS environments, in dedicated, segregated databases and server environments. Every customer runs on its own isolated infrastructure, separate from every other organization.
-
Encrypted in transit and at rest
Your data is encrypted with AES-256-GCM, both as it moves and where it's stored.
-
Limited internal access
Sensitive data sits in a secure database that only key personnel can access. Passwords and access keys are encrypted and reached only through secure means.
-
Independently assessed
SOC 2 Type II compliance, a CASA (Cloud Application Security Assessment) review, and annual penetration testing keep our practices checked against industry standards.
Private, including from AI.
-
Never used to train AI models
Your data is never used to train external large language models. Our contracts with AI providers prohibit using customer data for model training or sharing it outside approved processing.
-
Never shared across organizations
Your data never reaches another customer, not even in anonymized form.
-
Vendors get only what they need
We rarely share data with vendors. When we do, they get only the data relevant to the job, they're vetted (usually holding audits such as SOC 2 or PCI), and they're contractually barred from using it for anything else.
Held to the platforms' own rules.
-
Google data
Our use of data from Google APIs follows Google's API Services User Data Policy, including its Limited Use requirements. It's never used for advertising, and no one reads it without your agreement, except where security or the law requires it, or for internal operations on aggregated, anonymized data.
-
Chrome extension
The extension asks only for the permissions it needs, collects nothing in the background, and doesn't track your browsing on sites unrelated to FrontRace.
Questions from your security team?
We'll walk them through how FrontRace handles your data, start to finish. The full legal terms are in our Privacy Agreement.
Contact us