Only what we actually built.
No badge wall, no borrowed acronyms. Every control on this page exists in our code today and was checked against it before being written here. The data story (what we collect and why) lives in the privacy policy.
- 01
Your card never touches our servers
Payments run through Stripe’s hosted checkout page. Your card number goes to Stripe and stays there; we never see it and never store it. Prices are fixed on our server per tier, so a tampered request can’t change what you’re charged.
- 02
The scan can’t be aimed inward
The free scan fetches the URL you paste. That fetch speaks only http and https, refuses private and internal network addresses (including cloud metadata endpoints), and re-checks every redirect hop, so a bounce can’t smuggle the request somewhere it shouldn’t go.
- 03
Pages we read can't give Frank orders
Everything the scan pulls from the web is fenced off as untrusted data before the AI reads it. A page that tries to slip instructions to Frank ("ignore your rules", "reveal your prompt") gets treated as scraped spam and ignored.
- 04
The AI has no dangerous capabilities
By design, the prospect-facing AI can’t run code, touch files, move money, or reach into any system. Frank reads the scan, does arithmetic on your numbers, and talks. That’s the whole toolset.
- 05
Rate limits, a bot wall, and spend breakers
Public endpoints carry per-IP rate limits and the scan sits behind Cloudflare Turnstile. On top of that, daily spend circuit breakers cap what our AI can burn in 24 hours, so a flood degrades the service gracefully instead of running up a bill.
- 06
No passwords to steal
The client portal signs you in with a single-purpose magic link sent to your email. Links are cryptographically signed, expire after 30 minutes, and can’t be replayed as a session. There’s no password database to breach because there are no passwords.
- 07
Secrets stay out of the code
API keys and signing secrets live in server environment configuration, never in the codebase. The repository is private, and pushes deploy through Vercel with secrets injected at runtime.
- 08
Deletion on request
Email hello@4frntlabs.com and we permanently delete everything we hold about you, confirmed within 14 days. Server logs used for abuse detection auto-prune after 30 days on their own.
Four processors, no brokers
Four vendors process data on our behalf, each bound to use it only for our purposes. We don’t sell or rent your data to anyone.
- Anthropic · runs the AI behind Frank
- Supabase · database, hosted on AWS US-East
- Vercel · hosts the site and server code
- Resend · delivers transactional email
The full breakdown, including what you can request and how, is in the privacy policy.
What we don’t claim
We’re a small company and we won’t rent credibility we haven’t earned. So, in writing:
- No SOC 2 audit yet.
- No third-party penetration test to point at yet.
- Not a HIPAA business associate. If you run a healthcare practice, don’t share patient information with Frank.
When any of that changes, this page changes the same day. If you find a vulnerability, email hello@4frntlabs.com and you’ll reach a human who can actually fix it.
Questions? Ask a human.
hello@4frntlabs.com · we reply within 72 hours, usually faster.
Read the privacy policy