Security at Frequency

Your memory data is sensitive. We treat security as a core feature, not an afterthought.

Security features

Encryption Everywhere

TLS 1.3 in transit. AES-256 at rest. Your data is encrypted at every stage of the pipeline.

Tenant Isolation

Every tenant gets a unique ID and API key. Data is logically isolated — no cross-tenant access is possible.

Audit Logging

Every API call is logged with timestamps, tenant ID, and method. Full audit trail for compliance.

Rate Limiting

Per-tenant rate limits protect against abuse. Automatic throttling prevents denial-of-service.

API Key Rotation

Rotate your API keys at any time without downtime. Old keys are invalidated immediately.

Input Validation

All inputs are validated and sanitized at the edge. Schema validation on every request before processing.

Infrastructure security

Frequency runs entirely on Cloudflare's global network — the same infrastructure that protects millions of websites. Our Workers execute in V8 isolates, providing process-level isolation for every request.

We use Cloudflare D1 (SQLite at the edge) and KV for storage — both replicated globally with automatic failover. No single point of failure.

Our codebase undergoes regular security reviews. Dependencies are audited weekly and updated promptly when vulnerabilities are disclosed.

Responsible disclosure

If you discover a security vulnerability in Frequency, we ask that you report it responsibly. Please do not disclose the issue publicly until we've had a chance to address it.

Email security@frequency.dev with a description of the vulnerability, steps to reproduce, and any relevant details. We aim to acknowledge reports within 24 hours and provide a fix within 7 days for critical issues.

Secure AI memory, by default

Enterprise-grade security on every tier. Get started free.