Freakout AIFreakout AI

Security Checklist

Procurement and security review checklist for enterprise customers.

Platform scope#

  • Hosting model — Freakout hosts the enterprise room experience. Customers embed rooms on their own website through an iframe.
  • Primary region — Enterprise data is hosted on AWS Frankfurt (eu-central-1) by default. Enterprise contracts can scope dedicated infrastructure in other supported AWS regions, multi-Availability Zone coverage, custom domains, and CDN edge/POP requirements.
  • Regional scope — Supported enterprise deployment scopes include Europe, Americas, and MENA, subject to contract and implementation review.
  • Private assets — Product images, generated models, textures, and room media use private storage and signed URLs.
  • Optional AI — AI provider calls happen only when a generation, assistant, voice, or realtime feature is enabled and used.
  • Optional Shopify — Shopify data is processed only when a Shopify store is connected.

Security evidence package#

AreaCurrent positionEvidence or contract item
ISO 27001 / SOC 2Not certified; stack is prepared for formal auditAudit scope, auditor, target timeline
DPAStandard DPA access and coverage are documented in Data Processing AddendumSigned DPA, controller/processor roles, subprocessor terms
SubprocessorsCurrent provider list is documented in Compliance & GDPRProvider locations, transfer mechanisms, notice period
Data residencyPrimary hosting is AWS Frankfurt by defaultContract wording for requested region, Availability Zone coverage, custom domain, and CDN edge/POP requirements
Private asset storageEnterprise private assets use private storage and signed URLsBucket policy, public-access-block policy, signed URL TTL
Storage access logsPrivate asset storage events are logged separatelyLog destination, lifecycle policy, retention evidence
Application audit logsSecurity-relevant events are retained for 365 daysAudit event schema, export sample, lifecycle policy
Backup retentionMongoDB Atlas backup retention target is 24 hoursBackup policy, restore test evidence
RTO / RPORecovery targets are contract-specificRTO, RPO, escalation owner
SLA and supportSupport commitments are contract-specificSLA, support hours, severity definitions, escalation path
Incident response72-hour breach notification commitment is included in enterprise DPA termsIncident runbook summary, notification timeline
Admin accessAdministrative actions are audit-logged and privileged access is reviewedAccess review evidence, privileged role list
AI processingAI data flow is documented by featureProvider terms, opt-in feature list, data categories, training/retention position

Security questionnaire answers#

QuestionAnswer
Does the customer host the storefront?No. Freakout hosts the room experience; the customer embeds it through an iframe.
Are private assets public?No. Enterprise private assets are served through signed URLs after authorization checks.
Are camera frames uploaded for hand or pose interactions?No. Camera-driven interactions run in the visitor's browser.
Are AI features always on?No. AI provider calls happen only when the relevant feature is enabled and used.
Do AI providers train on customer data?Provider terms control this. OpenAI business/API, Google Gemini paid API, and Anthropic commercial terms restrict training use; Meshy requires vendor confirmation during enterprise review.
Is Shopify required?No. Enterprise iframe embeds can run without Shopify.
Are payment cards stored by Freakout?No. Stripe handles card data.
Are audit logs deleted with the account?No. Audit logs remain for the fixed security-log retention window.