We handle proposals and payment data from hundreds of sales teams. Here's how we keep it secure, and where we're candid about the work still ahead.
Frameboard runs on Netlify (edge delivery + serverless functions), Airtable (structured data), Mux (video), and Stripe (payments). All sub-processors are chosen for their security track record.
| Data type | Where it's stored | Encrypted at rest |
|---|---|---|
| User accounts, proposals, catalogue | Airtable (enterprise-plan, SOC 2 compliant) | Yes |
| Uploaded files (images, PDFs) | Netlify Blobs (AWS-backed) | Yes |
| Video | Mux (SOC 2 compliant) | Yes |
| Payment data | Stripe only - never touches our systems | Yes (PCI DSS Level 1) |
| Email logs | Resend (SOC 2 Type II) | Yes |
We do not sell data, share with advertisers, or use your proposal content to train external models. AI generations run on your content via API calls to model providers (currently Anthropic) that do not retain or train on the input beyond standard inference.
Our full policy set is versioned in git and reviewed annually. Each policy is written to be both operationally useful and audit-ready.
If we detect a security incident affecting customer data, we notify affected customers within 72 hours by email and via a banner on the app. Our internal incident response process is documented internally and exercised quarterly.
You can report suspected vulnerabilities to security@myframeboard.app. We review reports within one working day.
We'd rather have a real conversation than dodge one. Contact our team and we'll talk through your specific concerns.
Contact us