Security
Last updated: July 2026
This page summarises how Freakout protects customer data and responds to security issues. It is a trust summary, not a certification statement.
1. Security Programme
Freakout maintains security controls designed around ISO 27001, SOC 2, and GDPR requirements. Freakout does not claim ISO 27001 or SOC 2 certification or attestation.
- Customer data is encrypted in transit using TLS.
- Data is encrypted at rest where supported by our infrastructure and storage providers, including AWS-managed encryption.
- Personnel and systems use role-based access controls and least-privilege access.
- Access and activity are logged and monitored for security, operations, and service integrity.
- Incident response procedures cover identification, investigation, containment, remediation, and customer notice.
2. Data Hosting & Subprocessors
Primary customer data is hosted on MongoDB Atlas with encrypted managed backups. Infrastructure is hosted in the European Union where supported by the relevant service. We use subprocessors only where needed to provide, secure, or support the service.
- Amazon Web Services for hosting, storage, and CloudFront delivery.
- MongoDB Atlas for the primary customer database and encrypted managed backups.
- Stripe for payments. Card data is held by Stripe, never Freakout.
- Meshy for 3D model generation from submitted product images.
- OpenAI, Google, and Luma AI for AI generation features.
- Cloudflare for DNS, CDN, routing, and edge security services.
- Google for reCAPTCHA anti-abuse checks, Google Analytics, fonts, and other site resources.
- Vercel for website hosting, edge rendering, redirects, and static-page delivery.
- Shopify only for accounts that connect a Shopify store.
3. Logging & Retention
Security audit logs cover account activity such as sign-ins, administrative actions, billing changes, and data requests. They contain user IDs and one-way-hashed IP addresses, and do not contain message content, uploaded files, passwords, or payment data.
- Security audit logs are retained for 365 days.
- Deleted assets are permanently purged 30 days after deletion.
- Storage access logs are kept for 400 days.
- Standard server request logs are kept for security and operations only, never for advertising.
4. Incident Response
We notify affected customers of confirmed security incidents without undue delay, and no later than 72 hours after confirmation.
5. Contacts
Report suspected vulnerabilities or account security issues to security@freakout.ai. Send privacy rights requests to privacy@freakout.ai.