FRONiVA
July 2026
Security & Compliance

Your harvest data stays yours.

Froniva touches your pricing, your customers, and your ERP. The posture below is what we owe you in return — short, factual, and the same on every page.

01

Where your data lives.

Froniva runs on Railway, on Google Cloud infrastructure in europe-west4 — Netherlands. Every byte of customer data — your prices, your invoices, your CRM exports — is stored, processed, and backed up inside the EU. We do not replicate to US regions. We do not use US-based subprocessors for customer data storage.

Region
europe-west4 (NL)
Provider
Railway · Google Cloud infrastructure
Backups
EU-region only, encrypted
02

How it's encrypted.

TLS 1.3 in transit, AES-256 at rest. ERP credentials (Zoho OAuth refresh tokens, API keys, endpoints) are stored as encrypted per-service configuration — never in code repositories, never in client-side assets — and are used only in the moment of an authenticated API call. We do not log raw credential values, ever.

In transit
TLS 1.3
At rest
AES-256
Secrets
Encrypted per-service config, never in code
03

Human approval on price changes.

Every recommendation Froniva makes is pending until a named human approves it — recorded by user and timestamp. Recommendations with a delta beyond ±15% against the current item rate are routed to their own attention lane: excluded from any bulk approval, decided one by one. Fixed-price contract agreements require the account owner. Nothing writes silently.

04

The audit trail.

Every approval, every override, every sync to your ERP is logged with the recommending model run, the user who approved it, the original item rate, the new item rate, and the timestamp. The audit log is exportable as CSV at any time. We retain it for the lifetime of the contract plus seven years; you can also pull a complete copy on offboarding.

05

What the AI sees — and doesn't.

Recommendations come from a frontier large language model, accessed via API under a strict no-training-on-customer-data agreement — your prices, your invoices, your CRM data are never used to train anyone's models. The model sees only the structured numeric inputs needed to issue a recommendation (channel prices, segment bands, your historical margins, the day's wholesale prints). It does not see customer names, contact details, contract terms, or anything that resembles personal data.

06

GDPR & the analytics on this page.

Valstan GmbH (Flums, Switzerland) is the data controller. Customer-facing GDPR DPA is available on request and signed before any data exchange. The site you're reading uses Plausible Analytics — no cookies, no cross-site tracking, no personal data, EU-hosted. We don't use Google Analytics. We don't use Meta pixels. We don't run third-party advertising tags.

07

SOC 2 & ISO 27001 trajectory.

We are pre-SOC 2. The controls above (EU-only data residency, encryption, named-human approval, full audit trail, no-training AI tier, no third-party trackers) are the substance of what SOC 2 Type II eventually attests to. Formal SOC 2 Type I is on the 2026 roadmap; ISO 27001 follows in 2027 once the first cooperative deployments give us the production scale to defend the audit fee. We will publish the audit reports here when they exist; we will not claim them before they do.

08

Whose data is it.

Yours. Always. Your prices, your invoices, your CRM exports, your audit log, your scraper outputs — all of it remains your property. On contract end you receive a complete export within 30 days. We retain only what we are legally obligated to keep (fiscal records under Swiss + EU law); the rest is irrevocably deleted on confirmation.

09

Reporting a vulnerability.

If you find anything that looks like a vulnerability — in the platform, in this site, in our integrations — write to security@froniva.ai. We acknowledge within 24 hours and respond with a triage timeline within 72. Coordinated disclosure preferred; no bug bounty yet, but we credit publicly with permission and reciprocate seriously.

Last updated September 2026 · This page changes when our posture changes. The full audit log of changes is on request to security@froniva.ai.