Security
A review-gated account of the controls Defrost can support with current implementation evidence.
On this page
Current verified controls
Defrost uses tenant-scoped access controls and encrypts supported credentials at rest.
This is the approved public control statement for the current build. Other controls described in internal code or planning records are not public commitments until production evidence and authorized review agree.
Access and credential protection
Tenant context is applied to supported application data paths, and access is limited according to the role of the client or server operation. Supported credentials use authenticated encryption before storage.
These statements do not imply that every field, table, integration, or administrative path uses the same control. The final control annex must identify scope, exceptions, key ownership, and production validation.
Monitoring and resilience
Defrost has application checks, operational records, and recovery documentation for designated workflows. Monitoring coverage, backup configuration, recovery objectives, and drill results depend on the deployed environment and must be validated there.
This page does not state an uptime commitment, universal logging claim, completed recovery exercise, or availability service level.
Incidents and vulnerability reports
Suspected vulnerabilities or security incidents may be reported to support@defrostmail.com. Reports should include enough detail to reproduce or investigate the issue without accessing data beyond the reporter’s authorization.
Response ownership, escalation, disclosure coordination, and contractual notice timing require operator validation and counsel approval. This draft does not create a response-time promise or safe-harbor program.
Assurance and compliance boundaries
Defrost does not claim a security certification, independent audit, penetration-test result, universal legal compliance, or guaranteed protection on this page.
Product controls can support a customer’s compliance program but do not determine the customer’s obligations or make outreach lawful. External assurance may be described only when a current report and publication approval are recorded in the review ledger.
Procurement and contact
Procurement teams may send security and DPA questions to info@defrostmail.com. Privacy requests should be sent to privacy@defrostmail.com.
Evidence is shared only when it exists, is current, and is authorized for that audience. See the Data Processing Agreement and Sub-processors review status.
