Enterprise Security & Compliance Center

Security, Privacy, and Technical Architecture

Frosty Agent protects merchant workspaces through kernel-level PostgreSQL Row-Level Security, AES-256 encryption at rest, TLS 1.2+ in transit, and role-based access control with step-up multi-factor authentication. Customer documents and visitor conversations are never used to train foundation AI models under Section 12.4 of our Terms of Service.

TLS 1.2+ & HSTSEncrypted in transit with preloading
AES-256 at RestStorage layer cryptographic protection
PostgreSQL RLSKernel-enforced tenant isolation
Terms 12.4 Zero TrainingNever trained on customer data
Technical Controls

Security Architecture & Safeguards

Comprehensive security measures mapped directly to Privacy Policy Clause 14.

Encryption in Transit

All network transmissions use TLS 1.2 or higher with HSTS preloading enabled.

Connections between web visitors, client applications, and Frosty API servers are encrypted using Transport Layer Security (TLS 1.2+). HTTP Strict Transport Security (HSTS) is enforced with preloading, and all unencrypted HTTP traffic is redirected to HTTPS automatically.

Encryption at Rest

Primary database storage is encrypted with AES-256 at the storage layer.

All database tables, file attachments, and vector embeddings are encrypted at rest using industry-standard AES-256. Third-party OAuth tokens, WhatsApp credentials, and webhook signing secrets are additionally encrypted at the application layer with keys held separately from the data.

PostgreSQL Row-Level Security

Multi-tenancy is enforced inside the database engine, not just application logic.

Every merchant workspace is isolated via PostgreSQL Row-Level Security (RLS). Every query execution sets SET LOCAL app.merchant_id before running. Database kernel policies prevent one merchant from ever accessing, modifying, or querying another tenant’s data.

Least-Privilege Access Control

Role-based permissions and mandatory step-up multi-factor authentication.

Access to production systems is granted on a least-privilege basis and reviewed quarterly. Sensitive operations—such as API key rotation, subscription cancellation, and manual refunds—mandate step-up MFA (aal2 TOTP authentication). All personnel are bound by surviving written confidentiality agreements.

Strict AI Privacy & Data Handling

Your documents and visitor conversations are never used to train foundation AI models.

We do not sell personal data. We do not use your proprietary documents, knowledge bases, or visitor conversations to train or fine-tune foundation AI models. This commitment is guaranteed contractually in Section 12.4 of our Terms of Service and enforced across all sub-processor agreements.

Automated Backups & Recovery

Daily automated database snapshots with 30-day retention and point-in-time recovery.

Automated full database snapshots are taken daily at 02:00 UTC (07:30 IST) and preserved for 30 days in isolated, geo-redundant storage. Point-in-time recovery capabilities enable rapid restoration in the event of an infrastructure anomaly.

Zero AI Model Training Guarantee

Contractual Commitment · Terms of Service Section 12.4
Read Full Terms

Frosty Agent guarantees contractually that customer-uploaded knowledge bases, website product catalogs, quotation parameters, and end-user conversation histories are never utilized to train, retrain, evaluate, or fine-tune public or proprietary foundation artificial intelligence models.

Zero Data Retention for Training

Model inference requests are ephemeral and strictly governed under enterprise API agreements that prohibit provider-side caching for training.

Merchant Workspace Ownership

You retain complete intellectual property ownership over all knowledge base materials and customer records captured during your subscription.

Infrastructure & Partners

Data Residency & Sub-processors

Primary database storage is hosted in India (Mumbai), with 30-day advance notice for any sub-processor additions.

ProviderPurpose / Service AreaHosting RegionCategory
SupabasePrimary PostgreSQL database, authentication, and file storageIndia (Mumbai region)Primary Storage
GoogleAI model inference (Gemini) and Google Calendar OAuth connectivityOutside India (Standard Contractual Clauses / DPDP Rule 15)AI Inference
MetaWhatsApp Cloud API message routing and delivery, and advertising measurement / Conversions API (when enabled)Outside India (Standard Contractual Clauses / DPDP Rule 15)Messaging & Ads
RazorpayPayment gateway, subscription billing, and GST invoicingIndia (RBI localized payment processing)RBI & GST Compliant
ResendTransactional quotation and notification email deliveryUnited States (Encrypted transmission)Transactional Mail
UpstashDistributed Redis caching and sliding-window rate limitingRegional edge (Ephemeral in-memory cache)Edge In-Memory
Sub-processor Notification Policy: Merchants receive at least 30 days advance written notice before any new sub-processor is engaged.View Privacy Policy Clause 14
Incident Response

Breach Notification & Incident SLAs

Rigorous timelines for regulatory and merchant incident response.

24 Hours

Merchant Notification

Direct notification to designated merchant administrators following confirmation of any unauthorized access impacting workspace data.

72 Hours

DPBI Regulatory Notice

Formal notification to the Data Protection Board of India in accordance with the Digital Personal Data Protection (DPDP) Act 2023.

6 Hours

CERT-In Cybersecurity Notice

Reporting of specified cybersecurity incidents to the Indian Computer Emergency Response Team (CERT-In) under applicable directives.

Statutory Grievance Officer

Rule 3(2) IT Rules 2021 & Section 13 DPDP Act 2023

For regulatory inquiries, DPDP data subject rights requests, or grievance redressal, contact our designated Grievance Officer:

Officer: Anurag Tripathi

Designation: Grievance & Compliance Officer

Entity: Frostrek (India)

Address: 4th Floor, JMD Empire, 455 Golf Course Ext Rd, Sector 62, Gurugram, HR 122102

Vulnerability Disclosure & Safe Harbor

Coordinated Disclosure Policy

We welcome responsible security research. Frosty Agent operates a safe harbor policy for good-faith vulnerability reporting that adheres to standard disclosure practices.

Initial Response SLA: Within 24 hours

Status Updates: Weekly until remediation

Safe Harbor: No legal action against good-faith testing

Security FAQ

Frequently Asked Questions About Security & Compliance

Authored by Frostrek Information Security Team · Last Updated: September 2026