Security

A practical security approach, without inflated claims.

How Frictionite approaches website data today and the standards that will guide future customer-data handling.

Last updated: September 21, 2026

Security claims should be specific and verifiable. This page describes our current website-data approach and the controls we will document before Frictionite hosts customer packaging data. It is not a certification, audit report, or contractual security schedule.

Collect less to reduce risk

The public website is designed to collect only the information needed to begin a business conversation: name, company, email, optional phone number, and a short description of the EPR challenge. We do not ask visitors to upload packaging datasets or source files through the website.

Please do not submit credentials, sensitive personal information, confidential source files, or detailed customer data through the contact form.

Protect the information we receive

The website is served over HTTPS. Information submitted through the website is processed through Netlify Forms, and submission notifications are delivered to Frictionite through Google Workspace. Access is restricted to people and service providers who need the information to respond, operate the site, or protect its security.

Customer or prospect information submitted through frictionite.com is not used for AI model training.

Choose service providers deliberately

Hosting, form handling, email, analytics, and other providers can affect where data is processed and how it is protected. Frictionite uses Netlify for website hosting and form handling, Google Workspace for email, and, when a visitor consents, Google Tag Manager and Google Analytics 4 for website analytics. We evaluate providers for appropriate security and privacy practices and limit their use of information to the services they provide.

Separate website inquiries from customer data

The initial contact form is not a channel for transferring operational packaging data. If we agree to examine files as part of an early-customer engagement, the transfer method, permitted use, access, retention, and deletion expectations will be established separately before files are provided.

Before a hosted service handles customer data

Before Frictionite provides a hosted service that stores customer packaging information, we will document and validate the controls that apply, including:

  • Hosting regions and material subprocessors.
  • Encryption in transit and at rest.
  • Identity, authentication, and access controls.
  • Backup, recovery, logging, monitoring, and vulnerability management.
  • Retention, deletion, export, and account-closure procedures.
  • Incident assessment, response, and customer notification processes.

Those commitments will be reflected in customer-facing security documentation and agreements appropriate to the service being provided.

No certification claims

Frictionite Systems Inc. does not currently claim SOC 2, ISO 27001, or another independent security certification. If that changes, we will identify the exact certification, scope, and status rather than using broad labels such as “enterprise-grade security.”

Report a security concern

If you believe you have found a security issue involving the website, contact security@frictionite.com. Please provide enough information for us to understand and investigate the concern, but do not include sensitive data in the initial message.

Updates

We will update this page as Frictionite’s website, product, service providers, and implemented controls evolve. Security details in a signed customer agreement will take precedence over this general website page.