Skip to content
4FRNT
Security · Plain version

Only what we actually built.

No badge wall, no borrowed acronyms. Every control on this page exists in our code today and was checked against it before being written here. The data story (what we collect and why) lives in the privacy policy.

The controls
  • 01

    Your card never touches our servers

    Payments run through Stripe’s hosted checkout page. Your card number goes to Stripe and stays there; we never see it and never store it. Prices are fixed on our server per tier, so a tampered request can’t change what you’re charged.

  • 02

    The scan can’t be aimed inward

    The free scan fetches the URL you paste. That fetch speaks only http and https, refuses private and internal network addresses (including cloud metadata endpoints), and re-checks every redirect hop, so a bounce can’t smuggle the request somewhere it shouldn’t go.

  • 03

    Pages we read can't give Frank orders

    Everything the scan pulls from the web is fenced off as untrusted data before the AI reads it. A page that tries to slip instructions to Frank ("ignore your rules", "reveal your prompt") gets treated as scraped spam and ignored.

  • 04

    The AI has no dangerous capabilities

    By design, the prospect-facing AI can’t run code, touch files, move money, or reach into any system. Frank reads the scan, does arithmetic on your numbers, and talks. That’s the whole toolset.

  • 05

    Rate limits, a bot wall, and spend breakers

    Public endpoints carry per-IP rate limits and the scan sits behind Cloudflare Turnstile. On top of that, daily spend circuit breakers cap what our AI can burn in 24 hours, so a flood degrades the service gracefully instead of running up a bill.

  • 06

    No passwords to steal

    The client portal signs you in with a single-purpose magic link sent to your email. Links are cryptographically signed, expire after 30 minutes, and can’t be replayed as a session. There’s no password database to breach because there are no passwords.

  • 07

    Secrets stay out of the code

    API keys and signing secrets live in server environment configuration, never in the codebase. The repository is private, and pushes deploy through Vercel with secrets injected at runtime.

  • 08

    Deletion on request

    Email hello@4frntlabs.com and we permanently delete everything we hold about you, confirmed within 14 days. Server logs used for abuse detection auto-prune after 30 days on their own.

Who touches your data

Four processors, no brokers

Four vendors process data on our behalf, each bound to use it only for our purposes. We don’t sell or rent your data to anyone.

  • Anthropic · runs the AI behind Frank
  • Supabase · database, hosted on AWS US-East
  • Vercel · hosts the site and server code
  • Resend · delivers transactional email

The full breakdown, including what you can request and how, is in the privacy policy.

The honest part

What we don’t claim

We’re a small company and we won’t rent credibility we haven’t earned. So, in writing:

  • No SOC 2 audit yet.
  • No third-party penetration test to point at yet.
  • Not a HIPAA business associate. If you run a healthcare practice, don’t share patient information with Frank.

When any of that changes, this page changes the same day. If you find a vulnerability, email hello@4frntlabs.com and you’ll reach a human who can actually fix it.

Questions? Ask a human.

hello@4frntlabs.com · we reply within 72 hours, usually faster.

Read the privacy policy