Security at Frankee
Last Updated: May 14, 2026
This page summarizes how we approach security across our infrastructure, data handling, authentication, AI integration, and operations. For specific questions or to request preliminary compliance documentation, contact security@frankee.ai.
Compliance
Frankee is undergoing SOC 2 Type 2 audit in partnership with Vanta. Preliminary documentation, including in-place controls and audit status, is available on request to security@frankee.ai.
Infrastructure and Data Storage
Frankee runs on Render, with infrastructure hosted in the United States. All data is encrypted at rest using AES-256, and all connections are protected by TLS 1.2 or higher.
Customer data is stored in managed PostgreSQL databases isolated per organization. Database backups are managed by Render with point-in-time recovery, encrypted at rest, and retained according to our retention policy.
Data retention and deletion policies are available on request. Account and data deletion are available on request via security@frankee.ai.
Authentication
Frankee uses password-based authentication with industry-standard bcrypt hashing. All accounts require email verification before access is granted. Sessions are managed with JWT tokens with a two-hour expiration window.
Two-factor authentication is on our roadmap.
Passwords are never logged or stored in plain text, and all authentication traffic is encrypted in transit.
AI Vendor Disclosure
Frankee uses Anthropic's Claude API to power AI features including user story generation, retrospective analysis, and team assessments.
When you use these features:
- Your input, team context (members, products, framework), and generated outputs are sent to Anthropic
- Anthropic retains API data for 30 days for safety and abuse monitoring, after which it is deleted
- Anthropic does not train its models on API data
- Frankee's complete AI use disclosure is available at /ai-disclosure
Analytics
Frankee uses PostHog for product usage analytics, hosted in the United States. We send your user identifier, email, name, and role to PostHog to enable product improvement and customer support. Page-view autocapture is disabled - we explicitly choose which events and properties are captured.
We are planning to migrate to pseudonymized analytics identifiers in a future release.
User-Connected Integrations
Frankee supports optional connections to your team's project management tools:
- Jira (Cloud): OAuth 2.0 authorization, tokens encrypted at rest at the organization level
- Shortcut: API token authentication, encrypted at rest
You control these connections through your team settings and can disconnect at any time. Disconnecting immediately revokes Frankee's access.
Employee Access and Operational Controls
Production access is limited to authorized personnel. All access to production systems is logged and reviewed. Access to customer data is restricted to support cases where the customer has requested assistance, with audit trails maintained for accountability.
Production deployments are manual and reviewed prior to release. We do not auto-deploy to production environments.
Subprocessors
Frankee uses the following subprocessors:
| Subprocessor | Purpose | Region |
|---|---|---|
| Render | Hosting and managed PostgreSQL | United States |
| Anthropic | AI/LLM provider (Claude API) | United States |
| Resend | Transactional email delivery | United States |
| PostHog | Product analytics | United States |
| Vanta | Compliance automation | United States |
| Google Workspace | Internal company email | United States |
Responsible Disclosure
If you discover a security vulnerability in Frankee, please report it to security@frankee.ai. We commit to acknowledging your report within 24 hours and will not pursue legal action against good-faith research. Full guidelines: Responsible Disclosure Policy.
Contact
- Security questions or compliance documentation: security@frankee.ai
- Privacy inquiries: privacy@frankee.ai
- General support: support@frankee.ai