Security Overview
This document describes how Françoise (“we”, “us”, “our”) protects your data when you use our Service.
1. Architecture & Infrastructure
Cloud hosting (Azure)
Our backend runs on Microsoft Azure data centers located in the United States. Azure provides physical security, network isolation, and industry-standard certifications such as ISO 27001 and SOC reports for its infrastructure services.
Application architecture
- Backend services and databases are deployed in a hardened Azure environment.
- Access to production systems is restricted to a small number of authorized employees on a need-to-know basis.
- Customer workspaces are logically separated at the application level.
We do not operate a single-tenant infrastructure: data isolation between customers is enforced through our application architecture and access controls rather than separate physical environments.
2. Data Handling
2.1. Design systems
To run checks, Françoise stores a representation of your design system:
- Tokens
- Component definitions
- Rule configurations and related metadata
This data is used solely to validate your mockups against your design system. It is:
- Not shared with third parties, except with infrastructure providers that host our systems (e.g., Microsoft Azure)
- Deleted upon your written request or within a reasonable period after contract termination, subject to legal retention requirements
2.2. Mockups and layout fragments
Mockup images and layout fragments are processed ephemerally:
- Used only for the duration required to perform a specific check and return results
- Not written to long-term persistent storage as customer content
During Technical Validation and Business Proof phases, certain checks may use third-party AI services (such as Google Gemini) to assist with analysis. In such cases:
- Mockup content and layout fragments are transmitted over encrypted channels
- Data is processed strictly to fulfill the requested check in line with the provider’s enterprise data protection commitments
2.3. Analytics data
We retain anonymized, aggregated operational statistics, for example:
- Number of checks performed
- Distribution of error types
- Tool accuracy and performance metrics
- High-level feature usage patterns
These datasets do not identify individuals or specific customer organizations and are used only for internal analytics and product decisions.
2.4. Model training
We do not use your design system, mockups, layout fragments, or any customer content to train, fine-tune, or otherwise improve our machine learning models.
3. Access Control & Authentication
- Access to production infrastructure is limited to authorized personnel using individual accounts with strong authentication.
- Access is granted based on least privilege and reviewed periodically.
- Administrative operations are logged and monitored.
On the product side, customers can manage user access to their workspace (for example, adding/removing team members and configuring their roles).
4. Encryption & Network Security
- Data in transit between your client and our backend, as well as between our backend and third-party processors (Azure, Google Gemini), is protected using industry-standard encryption (e.g., HTTPS/TLS).
- Within Azure, we rely on secure networking configurations (virtual networks, access controls) to limit exposure of internal services.
We do not intentionally store sensitive customer content (such as mockup images or layout fragments) in long-term storage; design system representations and configuration data are stored in managed Azure services protected by Azure’s underlying security controls.
5. Application Security
- We follow secure development practices and code review processes to reduce the risk of introducing vulnerabilities.
- Identified security issues are triaged and remediated based on severity.
- We use logging and monitoring to detect anomalous behavior and operational issues in the application.
6. Third-Party Providers & Subprocessors
We rely on a small set of third-party providers to operate the Service:
- Microsoft Azure (United States) — infrastructure services (compute, storage, databases, networking)
- Google (United States) — Google Gemini APIs used for certain AI processing tasks during Technical Validation and Business Proof phases
These providers act as our subprocessors and are contractually bound to process data only on our instructions and to implement appropriate security measures. We maintain an up-to-date subprocessor list on our website and update it when we add or replace providers.
7. Incident Response
We maintain internal procedures designed to:
- Detect and investigate suspected security incidents
- Mitigate and remediate confirmed incidents
- Notify affected customers without undue delay when required by law or by our contractual commitments
If you believe your data may have been compromised, please contact us immediately at [email protected].
8. Customer Responsibilities
Security is a shared responsibility. We expect customers to:
- Control access to their Françoise workspaces (for example, managing who has access from their organization)
- Avoid uploading unnecessary personal or sensitive data into mockups and design system artifacts
- Notify us promptly if they suspect unauthorized access to their accounts
9. On-Premise Deployment
For customers with strict data residency or regulatory requirements, Françoise can be deployed as an on-premise solution inside the customer’s own infrastructure:
- All processing occurs within the customer’s environment (e.g., their own Azure subscription or data center)
- Customer controls infrastructure-level security (network, OS, Kubernetes, etc.)
- Françoise provides application-level configuration, update packages, and support
In the on-premise model, Françoise does not have direct access to the customer’s production data; security controls and compliance posture are primarily determined by the customer’s environment and configurations.
10. Contact
If you have questions about this Security Overview or require additional details for vendor security assessments, please contact:
Email: [email protected]