Your data is safe with us
Froovo is built on AWS with security at every layer — authentication, data isolation, encryption, and AI privacy protections baked in from day one.
AWS Cognito
Authentication
AES-256
Encryption at rest
TLS 1.2+
Encryption in transit
AWS Cloud
Infrastructure
Authentication
Froovo uses AWS Cognito for authentication — industry-standard OAuth 2.0 / OIDC with MFA support, secure session tokens, and automatic token rotation. Passwords are never stored in plaintext.
- AWS Cognito identity provider
- OAuth 2.0 / OIDC standard
- Multi-factor authentication (MFA)
- Secure session token management
- Automatic token expiry and rotation
- Social login with Google (optional)
Data Isolation
Every user's data is scoped to their organization. Our AppSync authorization rules enforce at the API layer that users can only read and write data within their own organization — no cross-tenant access is possible.
- Organization-scoped data at the API layer
- Owner-based authorization on all models
- AWS AppSync with Amplify auth rules
- No shared database tables across organizations
- Role-based access control (8 roles)
- Workspace-level permission scoping
Infrastructure
Built on AWS — the same cloud infrastructure trusted by Fortune 500 companies, healthcare providers, and governments worldwide. Data is stored in AWS DynamoDB and S3 with encryption at rest.
- AWS DynamoDB for all application data
- AWS S3 for document storage
- AWS Lambda for serverless compute
- Encryption at rest (AES-256)
- Encryption in transit (TLS 1.2+)
- AWS-managed key management (KMS)
AI & Data Privacy
When generating AI insights, Froovo only sends anonymized pipeline context to AI providers. PII — including email addresses, phone numbers, and full names — is never included in AI prompts.
- PII stripped from all AI context (email, phone)
- Only first names used in AI context
- Org-scoped context — no cross-org data
- All AI interactions logged to audit trail
- No training on your data
- Provider-agnostic AI abstraction layer
Audit Logging
Every AI interaction is recorded to an immutable audit log scoped to your organization. Froovo maintains activity timelines for all lead and transaction changes so nothing is ever lost.
- AI interaction audit log (AIInteraction model)
- Activity timeline on all leads
- Activity timeline on all transactions
- User action attribution
- Organization-scoped audit records
- Immutable event history
Compliance
Froovo is built with enterprise compliance in mind. Our architecture aligns with SOC 2 Type II controls and is designed to support real estate industry data regulations.
- SOC 2-aligned architecture
- OWASP Top 10 mitigations
- No injection vulnerabilities (parameterized queries)
- XSS protection via React rendering
- CSRF protections on API routes
- Secrets managed via environment variables only
Responsible Disclosure
If you discover a security vulnerability in Froovo, please report it responsibly to security@froovo.com. We take all reports seriously and will respond within 72 hours. Please do not publicly disclose the vulnerability until we have had a chance to address it.
Have security questions?
Our team is happy to answer any questions about our security architecture or compliance posture.
