LegalSecurity Overview
Reference
Security Overview
How Frabs protects the service and your data, in plain language, for your security review.
CurrentVersion 1 · October 2026In short
- At the hypervisorClause 2Nothing is installed inside a customer's VM. The sensor looks at flow metadata, not the content of traffic.
- Private by designClauses 2.4, 2.5The database cannot be reached from the internet, and administration happens only over an encrypted private tunnel.
- Multi-factor for everyoneClause 3.1Every user signs in with multi-factor authentication. It is not optional.
- Staff access is visibleClause 3.4Support views are read-only, need a recorded reason, last 30 minutes and appear in your own audit log.
- Separated and encryptedClause 4Each customer's data is kept apart by the database itself, and traffic is encrypted in transit.
- Report a vulnerabilityClause 10Use the contact page with Security as the topic. Good-faith reports are welcome.
This summary helps you find your way around. The PDF is the full legal text and is what applies.
What's inside
- 1About this document
- 2How the service is built
- 3Access and sign-in
- 4Protecting customer data
- 5Safe remediation
- 6Logging and monitoring
- 7Email security
- 8If something goes wrong
- 9What customers do
- 10Reporting a vulnerability
- 11Questions from customers
Version history
Frabs gives at least 30 days' notice before a new version takes effect.