Security

Security at Frictionless

Businesses trust Frictionless with their customers' messages. This page sets out the policies Geteazra LTD follows to protect that data. They are reviewed at least once a year and approved by the company's director.

Last updated 26 September 2026

1. Responsibility

A named security and data protection lead at Geteazra LTD owns these policies, makes sure they are followed, and is the contact for any security or privacy question. Everyone with access to production systems or customer data agrees to these policies before they get access.

2. Information security policy

  • We collect and access only the data needed to run the service, as described in our privacy policy.
  • Customer data is used only to provide Frictionless to the business it belongs to.
  • Every change to our code goes through version control and review before it is released.
  • Secrets such as API keys and encryption keys are kept in our hosting providers’ encrypted settings, never in code.
  • Production and staging run on separate servers and separate databases. Test work never touches production data.
  • This policy is reviewed at least once a year and whenever our systems change significantly.

3. Infrastructure and network security

  • Frictionless runs on established cloud providers: Vercel for the website, Render for our application servers, and Neon for our database (Frankfurt, Germany). Their data centres hold independent security certifications, and their networks include protection against denial-of-service attacks.
  • Our servers accept traffic only over HTTPS. Security headers, strict cross-origin rules and rate limits are applied to every request.
  • Webhooks from messaging platforms are verified by signature before we accept them.
  • The database accepts only encrypted, password-authenticated connections.

4. Data protection

  • All data in transit is encrypted with TLS 1.2 or higher.
  • All stored data is encrypted at rest with AES-256.
  • Access tokens for connected channels are encrypted again by our application with AES-256-GCM, so they are unreadable even to someone with database access.
  • Passwords are stored only as salted one-way hashes.
  • Each business’s data is isolated to its own workspace. Only members of that workspace can see it, and teammates get only the access their role needs.
  • Data is kept only as long as needed and deleted on request, as set out in our privacy policy and data deletion page.

5. Access control policy

Access to production systems and customer data follows need-to-know and least privilege.

  • Access is granted only to named people whose role requires it, at the lowest level that lets them do their job.
  • Shared accounts are not used. Every person has their own login.
  • Multi-factor authentication is required on every administrator account, including code hosting, cloud hosting, database and company email.
  • Passwords must be strong and unique, and are kept in a password manager.
  • Access is removed within one working day when someone leaves or no longer needs it.
  • All access is reviewed at least once a year, and access logs from our providers are retained.

6. Devices

  • Company devices run supported operating systems with automatic security updates.
  • Anti-malware protection is enabled and kept up to date, with regular scans.
  • Disks are encrypted, and screens lock automatically after at most 15 minutes of inactivity.
  • Everyone with access completes security awareness training at least once a year.

7. Vulnerability management

  • Our code dependencies are checked for known vulnerabilities before every release and at least monthly.
  • We run an external vulnerability scan of our public services at least once a quarter and keep the reports.
  • Critical and high-severity issues are fixed within 7 days; others are fixed in our normal release cycle.
  • If you find a security issue in Frictionless, please email michael@usefrictionless.com. We will acknowledge it within two working days and keep you updated until it is fixed.

8. Incident response policy

If we suspect that customer data has been accessed, changed or lost without permission, we:

  1. Contain it. Stop the incident, for example by revoking keys or tokens and blocking access.
  2. Assess it. Work out what happened, which data and which businesses are affected, and the risk to people.
  3. Notify. Tell affected businesses without undue delay, and within 72 hours of becoming aware of a breach. We also notify the Nigeria Data Protection Commission and other regulators where the law requires, and the messaging platforms involved (such as Meta or TikTok) as their terms require.
  4. Recover. Fix the cause, restore normal service, and check that the fix works.
  5. Learn. Record the incident, what we did and what we changed, and update these policies if needed.

We test this plan with a drill at least once a year and keep a record of every incident and drill.

9. Contact

Security or privacy questions, reports and requests: michael@usefrictionless.com. Geteazra LTD, Nigeria.