Security, Privacy, and Technical Architecture
Frosty Agent protects merchant workspaces through kernel-level PostgreSQL Row-Level Security, AES-256 encryption at rest, TLS 1.2+ in transit, and role-based access control with step-up multi-factor authentication. Customer documents and visitor conversations are never used to train foundation AI models under Section 12.4 of our Terms of Service.
Security Architecture & Safeguards
Comprehensive security measures mapped directly to Privacy Policy Clause 14.
Encryption in Transit
All network transmissions use TLS 1.2 or higher with HSTS preloading enabled.
Connections between web visitors, client applications, and Frosty API servers are encrypted using Transport Layer Security (TLS 1.2+). HTTP Strict Transport Security (HSTS) is enforced with preloading, and all unencrypted HTTP traffic is redirected to HTTPS automatically.
Encryption at Rest
Primary database storage is encrypted with AES-256 at the storage layer.
All database tables, file attachments, and vector embeddings are encrypted at rest using industry-standard AES-256. Third-party OAuth tokens, WhatsApp credentials, and webhook signing secrets are additionally encrypted at the application layer with keys held separately from the data.
PostgreSQL Row-Level Security
Multi-tenancy is enforced inside the database engine, not just application logic.
Every merchant workspace is isolated via PostgreSQL Row-Level Security (RLS). Every query execution sets SET LOCAL app.merchant_id before running. Database kernel policies prevent one merchant from ever accessing, modifying, or querying another tenant’s data.
Least-Privilege Access Control
Role-based permissions and mandatory step-up multi-factor authentication.
Access to production systems is granted on a least-privilege basis and reviewed quarterly. Sensitive operations—such as API key rotation, subscription cancellation, and manual refunds—mandate step-up MFA (aal2 TOTP authentication). All personnel are bound by surviving written confidentiality agreements.
Strict AI Privacy & Data Handling
Your documents and visitor conversations are never used to train foundation AI models.
We do not sell personal data. We do not use your proprietary documents, knowledge bases, or visitor conversations to train or fine-tune foundation AI models. This commitment is guaranteed contractually in Section 12.4 of our Terms of Service and enforced across all sub-processor agreements.
Automated Backups & Recovery
Daily automated database snapshots with 30-day retention and point-in-time recovery.
Automated full database snapshots are taken daily at 02:00 UTC (07:30 IST) and preserved for 30 days in isolated, geo-redundant storage. Point-in-time recovery capabilities enable rapid restoration in the event of an infrastructure anomaly.
Zero AI Model Training Guarantee
Contractual Commitment · Terms of Service Section 12.4Frosty Agent guarantees contractually that customer-uploaded knowledge bases, website product catalogs, quotation parameters, and end-user conversation histories are never utilized to train, retrain, evaluate, or fine-tune public or proprietary foundation artificial intelligence models.
Model inference requests are ephemeral and strictly governed under enterprise API agreements that prohibit provider-side caching for training.
You retain complete intellectual property ownership over all knowledge base materials and customer records captured during your subscription.
Data Residency & Sub-processors
Primary database storage is hosted in India (Mumbai), with 30-day advance notice for any sub-processor additions.
| Provider | Purpose / Service Area | Hosting Region | Category |
|---|---|---|---|
| Supabase | Primary PostgreSQL database, authentication, and file storage | India (Mumbai region) | Primary Storage |
| AI model inference (Gemini) and Google Calendar OAuth connectivity | Outside India (Standard Contractual Clauses / DPDP Rule 15) | AI Inference | |
| Meta | WhatsApp Cloud API message routing and delivery, and advertising measurement / Conversions API (when enabled) | Outside India (Standard Contractual Clauses / DPDP Rule 15) | Messaging & Ads |
| Razorpay | Payment gateway, subscription billing, and GST invoicing | India (RBI localized payment processing) | RBI & GST Compliant |
| Resend | Transactional quotation and notification email delivery | United States (Encrypted transmission) | Transactional Mail |
| Upstash | Distributed Redis caching and sliding-window rate limiting | Regional edge (Ephemeral in-memory cache) | Edge In-Memory |
Breach Notification & Incident SLAs
Rigorous timelines for regulatory and merchant incident response.
Merchant Notification
Direct notification to designated merchant administrators following confirmation of any unauthorized access impacting workspace data.
DPBI Regulatory Notice
Formal notification to the Data Protection Board of India in accordance with the Digital Personal Data Protection (DPDP) Act 2023.
CERT-In Cybersecurity Notice
Reporting of specified cybersecurity incidents to the Indian Computer Emergency Response Team (CERT-In) under applicable directives.
Statutory Grievance Officer
Rule 3(2) IT Rules 2021 & Section 13 DPDP Act 2023For regulatory inquiries, DPDP data subject rights requests, or grievance redressal, contact our designated Grievance Officer:
Officer: Anurag Tripathi
Designation: Grievance & Compliance Officer
Entity: Frostrek (India)
Address: 4th Floor, JMD Empire, 455 Golf Course Ext Rd, Sector 62, Gurugram, HR 122102
Vulnerability Disclosure & Safe Harbor
Coordinated Disclosure PolicyWe welcome responsible security research. Frosty Agent operates a safe harbor policy for good-faith vulnerability reporting that adheres to standard disclosure practices.
Initial Response SLA: Within 24 hours
Status Updates: Weekly until remediation
Safe Harbor: No legal action against good-faith testing